Enable Log Analysis for Cloud Firewall

Trend Cloud One™ – Conformity is a continuous assurance tool that provides peace of mind for your cloud infrastructure, delivering over 1000 automated best practice checks.

Risk Level: Medium (should be achieved)

Ensure that the Log Analysis feature is enabled for Cloud Firewall. Once the feature is enabled, the Cloud Firewall service integrates with Simple Log Service (SLS) to provide log analysis. It collects and stores inbound/outbound traffic logs in real-time, enabling querying, analysis, report generation, and alert configuration. Logs are also sent to downstream services for consumption, streamlining the process and allowing focus on analysis rather than manual tasks. Log Analysis is available only in Premium Edition, Enterprise Edition, and Ultimate Edition of Cloud Firewall that utilizes the subscription billing method.

Security

The Log Analysis feature is well-suited for enterprises and organizations needing network security compliance, flexible configuration, and comprehensive real-time monitoring and analysis of network traffic. Log Analysis it's ideal for:

  1. 1. Compliance audit: stores access logs for over six months, aiding compliance with data protection regulations and facilitating log audits.
    1. 2. Security analysis: traces, analyzes, and responds to security incidents swiftly, enhancing threat identification and prevention.
    2. 3. Data center integration: centralizes log management for improved data security.
    3. 4. Performance monitoring: real-time network performance monitoring and issue diagnosis for enhanced operational efficiency.

Audit

To determine if security log analysis is enabled for Cloud Firewall, perform the following operations:

Getting the Log Analysis feature configuration and status via Alibaba Cloud CLI (aliyun) is not currently supported.

Using Alibaba Cloud Console

01 Sign in to your Alibaba Cloud account.

02 Navigate to Cloud Firewall console available at https://yundun.console.aliyun.com/?p=cfwnext#/overview/home.

03 In the left navigation panel, under Log Analysis, choose Log Analysis.

04 On the Log Analysis page, check the Enable Now setting to determine if Log Analysis is enabled for Cloud Firewall. If the Enable Now setting is not active, the Log Analysis feature is not enabled for the Cloud Firewall service. If the Enable Now setting is not available, instead a Get Started page with an Upgrade Now button is displayed, Log Analysis is not enabled for Cloud Firewall. If the feature is enabled, check the Storage Usage indicator to determine the remaining log storage. If the Storage Usage indicator is at 100%, the log storage is exhausted, therefore, the Log Analysis feature is not operational.

Remediation / Resolution

To ensure that security log analysis is enabled for the Cloud Firewall service, perform the following operations:

Enabling the Log Analysis feature via Alibaba Cloud CLI (aliyun) is not currently supported.

Using Alibaba Cloud Console

01 Sign in to your Alibaba Cloud account.

02 Navigate to Cloud Firewall console available at https://yundun.console.aliyun.com/?p=cfwnext#/overview/home.

03 In the left navigation panel, under Log Analysis, choose Log Analysis.

04 On the Log Analysis page, choose Enable Now to enable the Log Analysis feature for the Cloud Firewall service. If the Enable Now setting is not available, choose Upgrade Now, select the Subscription tab, and choose Buy Now. On the subscription page, choose Subscription for Product Type, select the new Cloud Firewall plan from Current Version, and configure the quotas for different resources depending on your application requirements. Choose Yes for Log Analysis to enable Log Analysis and choose the necessary storage capacity from Log Storage. Choose Buy Now to upgrade your Cloud Firewall plan and enable the Log Analysis feature.

References

Publication date Apr 26, 2024