Help Center/ Log Tank Service/ Best Practices/ Log Ingestion/ Implementing Cross-Account Ingestion
Updated on 2026-06-22 GMT+08:00

Implementing Cross-Account Ingestion

In an enterprise, different departments or teams may use different Identity and Access Management (IAM) accounts to manage their resources. As a result, log data is scattered and difficult to manage and analyze in a unified manner. To solve this problem, Huawei Cloud Log Tank Service (LTS) provides cross-account log ingestion. With this function, you can implement unified management, real-time monitoring, and security isolation, thereby improving management efficiency and data security. This section describes how to use LTS to achieve cross-account ingestion.

Prerequisites

Two IAM accounts are available, which are account A and account B. Account A is the delegator account, and account B is the delegated account.

Restrictions

  • Before data synchronization is complete, data in the target and source log streams may be different. Check them one hour later.
  • Log stream mapping will not stop even when an agency becomes invalid. To stop mapping, manually disable or delete the ingestion task.

Creating an Agency

  1. Log in to the IAM console as account A (delegator account).
  2. On the IAM console, choose Agencies from the navigation pane on the left, and click Create Agency in the upper right corner.

  3. On the Create Agency page, configure the Agency Name, Agency Type, and Delegated Account. For details, see Creating an Agency and Assigning Permissions.

    The delegated account must be assigned the Agent Operator role for verification. During authorization, set the authorization scope to all resources for Agent Operator. After the authorization is successful, the Project [Region] of Agent Operator must be All resources [Regions of existing and future projects]. If not, re-assign the role by referring to Creating a User Group and Assigning Permissions.

Implementing Cross-Account Ingestion

  1. Log in to the LTS console as account B (delegated account).
  2. Choose Log Ingestion > Ingestion Center in the navigation pane and click Cross-Account Ingestion - Log Stream Mapping.

    Alternatively, choose Log Ingestion > Ingestion Management in the navigation pane and click Create. On the displayed page, click Cross-Account Ingestion - Log Stream Mapping.

  3. Configure agency parameters. After the configuration is complete, click Next: Log stream mapping.

    Table 1 Agency parameters

    Parameter

    Description

    Agency Name

    Name of the agency created by the delegator in IAM. A delegator account can create an agency to delegate resource management permissions to another account.

    Delegator Account Name

    Name of the delegator account, which is used for delegation verification.

  4. On the log stream mapping page, configure an ingestion rule. There are the following two configuration methods:

    • Automatic configuration
      1. Click Auto Configure.

      2. On the displayed page, set required parameters and click OK.
        Table 2 Parameters of automatic ingestion rule configuration

        Parameter

        Description

        Rule Name Prefix

        Enter a rule name prefix. In automatic configuration, ingestion rules with this prefix will be generated.

        Use only letters, digits, hyphens (-), underscores (_), and periods (.). Do not start with a period or underscore or end with a period. Max.: 59 characters. If you do not specify any prefix, default prefix rule will be used.

        Select the log groups or log streams that you want to ingest from the delegator account

        Up to 20 log groups or log streams can be selected.

        By default, the names of the target log groups and streams of the delegated account are the same as those of the source log groups and streams of the delegator account. Change them if needed.

      3. Click Preview.

        There are two types of preview results:
        • A new target log stream will be created: A target log group or log stream will be created in the delegated account.

        • An existing target log stream will be ingested: The target log group or log stream already exists in the delegated account.

      4. After the preview is complete, click Submit.

    • Manual configuration
      1. On the log stream mapping page, click Add Rule and set the rule by referring to Table 3.
        Table 3 Parameters for manual configuration

        Parameter

        Description

        Rule Name

        The default value is rule_xxx. You can also enter a custom name.

        Use only letters, digits, hyphens (-), underscores (_), and periods (.). Do not start with a period or underscore or end with a period. Enter 1 to 64 characters.

        Delegator Account

        Source Log Group

        Log group of the delegator account. Select an existing log group.

        Source Log Stream

        Log stream of the delegator account. Select an existing log stream.

        Delegated Account

        Target Log Group

        Log group of the delegated account. Select an existing log group or enter a name to create one.

        Target Log Stream

        Log stream of the delegated account. Select an existing log stream or enter a name to create one.

      2. Click Preview.
        There are two types of preview results:
        • A new target log stream will be created: A target log group or log stream will be created in the delegated account.
        • An existing target log stream will be ingested: The target log group or log stream already exists in the delegated account.
      3. After the preview is complete, click Submit and wait until the log ingestion task is created.

  5. Wait for data synchronization (within an hour).

    • If multiple log streams are ingested, click Back to Ingestion Configurations to view the log ingestion configuration list.

    • If a single log stream is ingested, click Back to Ingestion Configurations to view the log ingestion configuration and click View Log Stream to view ingested logs.

Viewing Ingested Logs

On the Ingestion Management page, view the ingested logs of different IAM accounts.
Figure 1 Ingested logs