For reliability and compliance purposes, ensure that your Simple Log Service (SLS) Logstores are configured with a log retention period of 365 days or more. In Alibaba Cloud, an SLS Logstore is used to collect, store, and query logs. Each Logstore belongs to an SLS project. The retention period represents the number of days to retain activity logs for a specific Logstore.
A retention period of 365 days or more should allow you to collect the necessary amount of activity log data useful to find any anomalies and potential security breaches. Because the average time to detect a breach is 200 days, your activity logs should be retained for 365 days or more in order to give you enough time to respond efficiently to any incidents.
Audit
To determine if your SLS Logstores have a sufficient retention period configured for log data, perform the following operations:
Remediation / Resolution
To extend the log data retention period for your Simple Log Service (SLS) Logstores, perform the following operations:
Creating and managing Simple Log Service (SLS) alerts via Alibaba Cloud CLI (aliyun) is not currently supported.References
- Alibaba Cloud Documentation
- What is Simple Log Service?
- Project
- Logstore
- Resource management overview
- Manage a Logstore
- SLS CLI Documentation
- list_project
- list_logstore
- get_logstore
- update_logstore