MindMap Gallery Alibaba Cloud Log Service SLS
Simple Log Service (SLS) is a cloud-native observation and analysis platform that provides large-scale, low-cost, real-time platform services for Log/Metric/Trace and other data. It provides one-stop data collection, processing, analysis, alarm visualization and delivery functions, comprehensively improving the digital capabilities of R
Edited at 2024-01-13 15:13:18One Hundred Years of Solitude is the masterpiece of Gabriel Garcia Marquez. Reading this book begins with making sense of the characters' relationships, which are centered on the Buendía family and tells the story of the family's prosperity and decline, internal relationships and political struggles, self-mixing and rebirth over the course of a hundred years.
One Hundred Years of Solitude is the masterpiece of Gabriel Garcia Marquez. Reading this book begins with making sense of the characters' relationships, which are centered on the Buendía family and tells the story of the family's prosperity and decline, internal relationships and political struggles, self-mixing and rebirth over the course of a hundred years.
Project management is the process of applying specialized knowledge, skills, tools, and methods to project activities so that the project can achieve or exceed the set needs and expectations within the constraints of limited resources. This diagram provides a comprehensive overview of the 8 components of the project management process and can be used as a generic template for direct application.
One Hundred Years of Solitude is the masterpiece of Gabriel Garcia Marquez. Reading this book begins with making sense of the characters' relationships, which are centered on the Buendía family and tells the story of the family's prosperity and decline, internal relationships and political struggles, self-mixing and rebirth over the course of a hundred years.
One Hundred Years of Solitude is the masterpiece of Gabriel Garcia Marquez. Reading this book begins with making sense of the characters' relationships, which are centered on the Buendía family and tells the story of the family's prosperity and decline, internal relationships and political struggles, self-mixing and rebirth over the course of a hundred years.
Project management is the process of applying specialized knowledge, skills, tools, and methods to project activities so that the project can achieve or exceed the set needs and expectations within the constraints of limited resources. This diagram provides a comprehensive overview of the 8 components of the project management process and can be used as a generic template for direct application.
Alibaba Cloud Log Service SLS
Product introduction
Log Service SLS is a cloud-native observation and analysis platform that provides large-scale, low-cost, real-time platform services for Log, Metric, Trace and other data. The log service provides one-stop functions such as data collection, processing, query and analysis, visualization, alarms, consumption and delivery, comprehensively improving your digital capabilities in R&D, maintenance, operations, security and other scenarios.
Feature overview
data collection
It supports data types such as Log, Metric, and Trace, and supports more than 50 data sources, including Alibaba Cloud products, servers and applications, IoT devices, mobile terminals, open source software, standard protocols, etc.
Log storage
Supports intelligent tiered storage. When data is stored in layers, it can reduce your long-term storage costs while ensuring that log query, analysis, visualization, alarm, delivery and processing capabilities are not affected.
data processing
It provides more than 200 built-in functions, more than 400 regular expressions, and flexible custom functions to achieve effects such as filtering, splitting, conversion, enrichment, and copying, and meets scenarios such as data distribution, regularization, and fusion.
Query and analysis
It supports real-time query and analysis of PB-level data, provides more than 10 query operators, more than 10 machine learning functions, more than 100 SQL functions, and supports scheduled SQL and SQL exclusive versions.
Visualization
It supports the visualization of query and analysis results, provides more than 10 kinds of statistical charts, including tables, line charts, histograms, maps, etc., and supports customized dashboards based on statistical charts (supports embedded and drill-down analysis).
Alarm
Provides one-stop alarm functions, including alarm monitoring, alarm management, notification (action) management, etc., suitable for multiple scenarios such as development operation and maintenance, IT operation and maintenance, intelligent operation and maintenance, security operation and maintenance, and business operation and maintenance.
Consumption and delivery
Supports real-time data consumption, suitable for Storm consumption, Flume consumption, Flink consumption and other scenarios; supports real-time data delivery, suitable for delivering data to OSS, TSDB and other cloud products.
Log audit
On the basis of inheriting all functions of the existing log service, it also supports real-time automated and centralized collection of cloud product logs under multiple accounts and auditing, as well as storage, query and information summary required for auditing.
Features
data collection
Supports collection of logs, time series data and link data related to servers and applications.
Supports collection of IoT device logs.
Supports collection of Alibaba Cloud product logs.
Supports collection of mobile data.
Supports collecting data from open source software such as Logstash, Flume, Beats, FluentD, Telegraf, etc.
Supports data access through standard protocols such as HTTP, HTTPS, Syslog, Kafka, and Prometheus.
Query and analysis
Supports precise query, fuzzy query, full-text query, and field query.
Supports contextual query, log clustering, LiveTail, index rebuilding and other functions.
Supports standard SQL 92 syntax.
Provides SQL exclusive instances.
data processing
Data curation: perform field extraction and format conversion for logs in chaotic formats, and obtain structured data to support subsequent stream processing and data warehouse calculations.
Data enrichment: Perform field joins (JOIN) on logs (such as order logs) and dimension tables (such as user information tables) to add more dimensional information to the logs for data analysis.
Data flow: Transmit logs from overseas regions to central regions through the global acceleration function to achieve centralized management of global logs.
Data desensitization: Desensitize sensitive information such as passwords, mobile phone numbers, and addresses contained in the data.
Data filtering: Filter out logs of key services for focused analysis.
Consumption and delivery
Supports data consumption through third-party software such as Splunk, QRadar, Logstash, and Flume.
Supports data consumption through Java, Python, GO and other languages.
Supports data consumption through Alibaba Cloud products such as function computing, real-time computing, and cloud monitoring.
Supports data consumption through streaming computing platforms such as Flink, Spark, and Storm.
Supports data delivery to OSS, MaxCompute, AnalyticDB, TableStore and other Alibaba Cloud products.
Visualization
Built-in charts in the dashboard: Log Service provides you with a variety of statistical charts such as tables, line charts, and bar charts. You can select appropriate chart types to display query and analysis results based on your analysis needs, and save the results to the dashboard.
Third-party visualization tools: Log Service supports direct connection with third-party charts such as Grafana and DataV.
Alarm
Alarm monitoring: Supports regular inspection, evaluation, query and analysis results through alarm monitoring rules, triggers alarms or recovery notifications, and sends them to the alarm management system.
Alarm management: Supports routing, suppression, deduplication, silencing, merging and other operations for received alarms through alarm policies, and then sends them to the notification (action) management system.
Notification (action) management: Supports dynamic allocation of alarms to specific notification channels through action policies, and then notifies target users, user groups or duty groups.
Log audit
Supports real-time automated and centralized collection of cloud product logs under multiple accounts and auditing.
Covering basics (ActionTrail, Container Service Kubernetes version), storage (OSS, NAS), network (SLB, API gateway), database (relational database RDS, cloud native distributed database PolarDB-X, PolarDB MySQL cloud native database), security (WAF, DDoS protection, cloud firewall, cloud security center) and other cloud products.
Supports free docking with other ecological products or own SOC center.
Hundreds of built-in alarm rules support one-click activation, covering compliance monitoring in all aspects such as account security, permission management, storage, host, database, network, logs, etc.
Product architecture and advantages
product architecture
Product advantages
unified access
Supports multiple types of data access from multiple sources.
intelligent
Provide complete AIOps capabilities and support intelligent anomaly detection and root cause analysis capabilities.
Efficient
Provides real-time collection, query and analysis capabilities for hundreds of billions of data.
one stop shop
Provide one-stop data functions, including data collection, processing, query and analysis, visualization, alarms, etc.
elasticity
Provides PB-level data elastic scalability.
low cost
Supports pay-as-you-go. You only pay for what you actually use, reducing the total cost of ownership (TCO) by more than 50%.
Application scenarios
Data collection and consumption
Through the log service LogHub function, various real-time log data (including Metric, Event, BinLog, TextLog, Click, etc.) can be accessed on a large scale and at low cost.
Easy to use: Provides 50 real-time data collection methods, allowing you to quickly build a platform; powerful configuration management capabilities reduce the burden of operation and maintenance.
Elastic scaling: Whether it is traffic peaks or business growth, it can easily cope with it.
Data cleaning and stream computing (ETL/Stream Processing)
Log Hub (LogHub) supports docking with various real-time computing and services, and provides complete progress monitoring, alarm and other functions, and can realize customized consumption based on SDK/API.
Easy to operate: Provides rich SDK and programming framework, seamlessly connects with various stream computing engines.
Monitoring and alarming: Provides rich monitoring data and delayed alarm mechanism.
Elastic scaling: PB-level elasticity, 0 latency.
Data warehouse docking (Data Warehouse)
The LogShipper function can deliver data in the LogHub to storage services. The process supports various storage formats such as compression, custom Partition, and row and column.
Massive data: There is no upper limit on the amount of data.
Rich types: supports various storage formats such as rows, columns, TextFile, etc.
Flexible configuration: supports user-defined partition and other configurations.
Log real-time query and analysis
Real-time query analysis (LogAnalytics) can index data in LogHub in real time and provide rich query methods such as keywords, fuzzy, context, range, and SQL aggregation.
Strong real-time performance: you can query it after writing.
Massive and low-cost: supports PB/Day indexing capability, the cost is 15% of the self-built solution.
Strong analytical capabilities: supports multiple query methods, and SQL for aggregation analysis, and provides visualization and alarm functions.