Docs
EN
Docs
Console
Sign in
Torch Log Service
Document
Torch Log Service
Torch Log Service
Document
Product News
New feature release notes
Product announcement
Announcement on the cancellation of the free quota for TOS log management
TLS Architecture upgrade notification
Product Overview
What is Torch Log Service
Product features
Application scenarios
Product advantages
Basic concepts
Limits
Product Billing
Billing overview
Billing items
Billing items based on pay-by-feature mode
Billing items based on pay-by-ingested-data mode
Billing examples
Billing examples based on pay-by-feature mode
Billing examples based on pay-by-ingested data mode
Overdue payments
Getting Started
Overview
Create resources
Collect log data
Configure indexes
Query and analyze logs
User Guide
Smart assistant copilot
Resource management
Log project
Log topic
Metric topic
Host group
Host group overview
Create host group (IP address)
Create host group (Host identification)
View host group
Modify host group
Delete host group
Manage shards
Tag management
Tag overview
Binding tags
Filter resources by tags
Edit or unbind tags
Apply for resource quota
Console overview
Data collection
Collection overview
LogCollector collection
Introduction to LogCollector
LogCollector limits
LogCollector versions
Installation and upgrade
Install LogCollector (host machine)
Upgrade LogCollector (host machine)
Install LogCollector (DaemonSet deployment)
Install LogCollector (Sidecar deployment)
Install LogCollector CRD
Upgrade LogCollector (Kubernetes cluster)
Collect host logs
Single-line full text mode
Multi-line full text mode
JSON mode
Separator mode
Single-line complete regex mode
Multi-line complete regex mode
NGINX configuration mode
Collect container logs
Container collection overview
LogCollector CRD collection mechanism
Collect container text logs (DaemonSet - Console method)
Collect container standard output (DaemonSet - Console method)
Collect container logs (DaemonSet - Pod environment variable method)
Collect container logs (DaemonSet - CRD method)
Collect container logs (Sidecar - Console method)
Collect container logs (Sidecar - CRD method)
Collect metric topic data
LogCollector plugins
Plugin overview
Process logs using LogCollector plugins
Plugin execution conditions
Field extraction plugin
JSON parsing plugin
Add field plugin
Data desensitization plugin
String replacement plugin
Time parsing plugin
Rename plugin
Log filtering plugin
Drop field plugin
IP address conversion plugin
JSON extraction plugin
Field splitting and reassembly plugin
URL parsing plugin
Field retention plugin
Manage LogCollector
LogCollector collection configuration management
Configure LogCollector startup parameters
Create anonymous identifiers to collect logs without AKSK
general reference
Time format
Container log path placeholder
Obtain container labels and environment variables
Aggregation rules for multi-line full text logs
Set IP addresses for hosts or containers
Relation between container standard output and log levels
Collect multiple log files or standard output simultaneously
Data import
Import logs from SLS
Import logs from TOS
Import data from Kafka
Import data from Elastacsearch
Cloud product log collection
Cloud product log collection
TOS log collection
Collect TOS logs
Manage TOS log resources
DBW log collection
Collect DBW logs
Manage DBW log resources
VPN Log collection
Collect VPN logs
Manage VPN log resources
VKE log collection
Collect VKE logs
Manage VKE log resources
CLB log collection
Collect CLB logs
Manage CLB log resources
CloudTrail log collection
Collect CloudTrail logs
Manage CloudTrail log resources
CFW log collection
Collect CFW logs
Manage CFW log resources
NTA log collection
Collect NTA logs
Manage NTA log resources
ALB log collection
Collect ALB logs
Manage ALB log resources
APMPlus log collection
Collect APMPlus logs
Manage APMPlus log resources
veFaaS log collection
Collect veFaaS logs
Manage veFaaS log resources
veImageX log collection
Collect veImageX logs
Manage veImageX log resources
VPC log collection
Collect VPC logs
Manage VPC log resources
TrafficRoute DNS log collection
Collect TrafficRoute DNS logs
Manage TrafficRoute DNS log resources
DDoS log collection
Collect DDos logs
Manage DDoS log resources
DCDN log collection
Collect DCDN logs
Manage DCDN log resources
WAF log collection
Collect WAF logs
Manage WAF log resources
Multi-cloud security platform log collection
Collect multi-cloud security platform logs
Managing multi-cloud security platform log resources
APIG log collection
Collect APIG logs
Manage APIG log resources
Machine learning task log collection
Collect machine learning task logs
Manage machine learning task log resources
Volcano Ark application lab log collection
Collect Volcano Ark Application Lab logs
Manage Volcano Ark Application Lab log resources
CR log collection
Collect CR logs
Manage CR log resources
FileNAS log collection
Collect FileNAS logs
Manage FileNAS log resources
LLM Application Firewall Service log collection
Collect LLM Application Firewall Service logs
Manage LLM Application Firewall Service log resources
vePFS log collection
Collect vePFS logs
Manage vePFS log resources
Cloud security center log collection
Collect Cloud Security Center logs
Manage Cloud Security Center log resources
EFS log collection
Collect EFS logs
Manage EFS log resources
Upload logs using the Kafka protocol
Use WebTracking to collect logs
Upload logs using Logback Appender
Upload logs using Log4j2 Appender
Upload logs using Syslog protocol
Import SLS collection configuration
Data storage
Storage types
Data tamper-proof
Data encryption
Query and analysis
Query and analysis workflow
Configure log indexes
Index data types
Configure indexes
Rebuild index
Reserved field
Query log
Query overview
Query syntax
Single-topic log query
Multi-topic log query
Query logs via phrase query
Query logs via phrase query (Index edition)
Query the context of specified log
Analyze logs
Analysis overview
Analysis syntax
Log analysis
Asynchronous query and analysis of logs
Quick analysis for specified log fields
Use third-party tools to query and analyze logs
TLS Elasticsearch-compatible API
Configure Kibana query logs
Associate external data source for log query
Associate to MySQL data source
MySQL join query and analysis
Query and analyze metric topic
Quickly set up query and analysis statements using tap mode
Scroll logs in real time using LiveTail
Analyze data using log clustering
Download logs
SQL function
Functions overview
Aggregate functions
Date and time functions
String functions
Regular expression functions
Year-on-year and period-on-period functions
Mathematical calculation functions
Mathematical statistics functions
Array functions
Map functions
JSON functions
IP functions
URL function
Approximate functions
Binary functions
Bitwise functions
Geo functions
Color processing functions
phone number functions
Unit conversion functions
Window funnel functions
Window functions
Type conversion functions
HyperLogLog functions
Lambda expressions
Arithmetic operation syntax
Comparison operators
Logical operators
Conditional expressions
SQL syntax
SELECT syntax
WHERE syntax
AS syntax
GROUP BY syntax
ORDER BY syntax
LIMIT syntax
DISTINCT clause
JOIN clause
UNION clause
Having clause
Subqueries
SQL reserved words
Machine learning function
Overview of machine learning functions
Prediction and anomaly detection function
Time series clustering functions
Anomaly comparison function
Threshold recommendation function
Difference pattern statistical functions
Visualization
Query and analysis charts
Overview of query and analysis charts
Configure data classification charts
Configure data aggregation chart
Configure data analysis charts
Summaries of query and analysis charts
Table
Line chart
Bar chart
Flow chart
Pie chart
Single value chart
China map
World map
Thermal map
Histogram
Progress bar
Rectangle Tree chart
Statistics chart
Measurement chart
Timeline
Radar chart
Scatter chart
Funnel Chart
Text chart
Topology diagram
Word cloud
Sankey diagram
Crosstab
Create dashboard
Create a blank dashboard
Quickly create a dashboard using a preset template
Import dashboard
Use dashboard
Common dashboard actions
Add charts to dashboard
Export dashboards in Grafana format
Configure drill-down events for dashboard chart
Subscribe to dashboard messages
Password-free dashboard sharing
Dashboard JSON Model description
Log field description for preset dashboard
Add dashboard filters and variables
Introduction to dashboard filters and variables
Add dashboard filter
Add custom variables to dashboard
Add dashboard data source variables
Use preset system variables
Create variable cascade relationships
Add time series filter
Use other systems to analyze logs
Embed externally built systems into TLS console
Embedded parameter details in TLS Console
Visualize and analyze logs via Grafana
Log applications
Overview of log applications
Log applications list
CloudLens for TLS
CloudLens for TOS
CloudLens for VKE
CloudLens for EBS
CloudLens for ALB
CloudLens for CLB
OpenClaw Observability
VeADK observability
LLM application monitoring
Trace call chain analysis
NGINX access monitoring
JuiceFS access analysis
MQTT monitoring
Integrate OpenClaw observation
Data processing
Data transformation
Data transformation overview
How data transformation works
Configure cross-account data transformation permissions
Create data transformation task
Manage data transformation tasks
View data transformation progress and status
Syntax and functions
Data transformation syntax
Functions overview
Global operation function
Flow control function
Event handler function
Event check function
Field processing function
Field check function
Key-value extraction function
Enrichment mapping function
expression function
Date value processing function
String processing functions
Type conversion functions
Logical expression functions
Arithmetic expression functions
Regular expression functions
Dictionary functions
Encoding and decoding function
IP address parsing functions
Parsing functions
Data structuring functions
list functions
resource function
Data transformation performance guide
Data processing best practices
Data filtering
Data flow
Data masking
general reference
Query string syntax
Regular expression
Data write processor
Write processor overview
Create a write processor
Associate write processor
Manage write processors
Data consumer processor
Consumer processor overview
Create consumer processor
Manage consumer processor
Timed SQL Analysis
Scheduled SQL analysis overview
Principles of work
Create schedule SQL analysis and store data in topic
Create scheduled SQL analysis and store data in managed Prometheus
Manage scheduled SQL analysis tasks
Select time zone
SQL time window syntax
Data backflow
Data backflow overview
Create data backflow task
Create log backflow task for Volcanoengine Ark high-code application
Manage log backflow task
Data consumption and shipping
Data consumption and shipping overview
Consume logs using ConsumeLogs
Consume data via consumer group
Consume logs via Kafka protocol
Consume log data through Function Service
Ship logs to TOS
Overview of shipping logs to TOS
Configure cross-account log shipping permissions
Ship logs in JSON format
Ship logs in CSV format
Ship data in Parquet format
Manage shipping configurations
Decompress Snappy-compressed files
Ship logs to Kafka
Overview of shipping logs to Kafka
Configure cross-account log shipping permissions
Ship logs to Message Queue for Kafka
Manage Kafka shipping rules
Ship logs to Splunk
Ship logs to Splunk using SDK
Ship logs to Splunk using Add-On plugin
Alarm
Alarm overview
Quickly configure log alarm
Alarm policy
Create alarm policy
Manage alarm policy
Monitor alarm policy
Multi-statement set operation
Triggering condition expression
Timeliness of alarm monitoring task
Alarm policy testing
Alarm notification content template
Notification content overview
Create content templates
Content syntax
Content variable
Content functions
Login-free access to the alarm details page
View alarm execution results
View alarm history
Alarm notification content
Manage content template
alarm notification channel
Create notification group
Manage notification group
Create Webhook integration configuration
Tracing service
Trace feature overview
Trace data format
Create a universal trace instance
Create trace instance for VolcanoEngine Ark high-code application
Manage trace instances
Write data via OpenTelemetry SDK
View trace data via Grafana
Monitor Log Service
View cloud monitoring data
Service log
Service log overview
Enable or disable LogCollector service logs
Service log fields
Service log dashboard
Permission management
IAM overview
Authorized actions
Authorizable resources
Examples of custom permission policy
Cross-service access authorization
API reference
API overview
API release history
API list
Invocation method
Request structure
Common parameters
Calculating a signature
Response message
Endpoint
Appendix
Common error codes
Data encoding method
Project management API
CreateProject
DeleteProject
ModifyProject
DescribeProject
DescribeProjects
Topic management API
CreateTopic
DeleteTopic
ModifyTopic
DescribeTopic
DescribeTopics
Shard management API
DescribeShards
ManualShardSplit
ManualMergeShard
Index management API
CreateIndex
DeleteIndex
ModifyIndex
DescribeIndex
Log management API
PutLogs
DescribeCursor
ConsumeLogs
SearchLogs
DescribeLogContext
DescribeHistogramV1
DescribeHistogram
WebTracks
CreateDownloadTask
DescribeDownloadTasks
DescribeDownloadUrl
CancelDownloadTask
Host group management API
CreateHostGroup
DeleteHostGroup
ModifyHostGroup
DescribeHostGroup (Deprecated)
DescribeHostGroupV2
DescribeHostGroups (deprecated)
DescribeHostGroupsV2
DescribeHosts
DeleteHost
DescribeHostGroupRules
ModifyHostGroupsAutoUpdate
DeleteAbnormalHosts
Collection configuration management API
CreateRule
DeleteRule
ModifyRule
DescribeRule (deprecated)
DescribeRuleV2
DescribeRules
ApplyRuleToHostGroups
DescribeBoundHostGroups
DeleteRuleFromHostGroups
Data import API
CreateImportTask
DeleteImportTask
ModifyImportTask
DescribeImportTask
DescribeImportTasks
Data processor API
CreateProcessor
ModifyProcessor
BindTopicProcessor
BatchBindTopics
ExecProcessor
OperateProcessor
UnbindTopicProcessor
DeleteProcessor
DescribeProcessor
DescribeProcessors
DescribeTopicsByProcessor
DescribeProcessorFunctions
DescribeProcessorByTopic
DescribeProcessorBindings
Data transformation API
CreateETLTask
DeleteETLTask
ModifyETLTask
DescribeETLTask
DescribeETLTasks
ModifyETLTaskStatus
Data shipping API
CreateShipper
DeleteShipper
ModifyShipper
DescribeShipper
DescribeShippers
Data backflow API
CreateLogBackFlowTask
DeleteLogBackFlowTask
DescribeLogBackFlowTasks
ModifyLogBackFlowTask
SQL analysis API
CreateScheduleSqlTask
ModifyScheduleSqlTask
DeleteScheduleSqlTask
DescribeScheduleSqlTask
DescribeScheduleSqlTasks
Alarm management API
CreateAlarmNotifyGroup
DeleteAlarmNotifyGroup
ModifyAlarmNotifyGroup
DescribeAlarmNotifyGroups
CreateAlarm
DeleteAlarm
ModifyAlarm
DescribeAlarms
CreateAlarmContentTemplate
DeleteAlarmContentTemplate
ModifyAlarmContentTemplate
DescribeAlarmContentTemplates
CreateAlarmWebhookIntegration
DeleteAlarmWebhookIntegration
DescribeAlarmWebhookIntegrations
ModifyAlarmWebhookIntegration
Consumer group management API
CreateConsumerGroup
DeleteConsumerGroup
DescribeConsumerGroups
ModifyConsumerGroup
ConsumerHeartbeat
DescribeCheckPoint
ModifyCheckpoint
ResetCheckpoint
Kafka protocol consumption API
OpenKafkaConsumer
CloseKafkaConsumer
DescribeKafkaConsumer
Tag management API
AddTagsToResource
RemoveTagsFromResource
UntagResources
TagResources
ListTagsForResources
Trace storage API
CreateTraceInstance
ModifyTraceInstance
DeleteTraceInstance
DescribeTraceInstances
DescribeTraceInstance
DescribeTrace
SearchTraces
Account management API
ActiveTlsAccount
GetAccountStatus
SDK reference
SDK overview
Configure identity authentication
Go SDK
Go SDK overview
Install TLS SDK for Go
Getting started
Use TLS SDK for Go to create basic resources
Use TLS SDK for Go to write logs
Use TLS SDK for Go to consume logs
Use TLS SDK for Go to query and analyze logs
Use TLS SDK for Go consumer groups to consume logs
Import the TOS data via Go SDK
Import Kafka data using the Go SDK
Send logs to TOS using Go SDK
Using the Go SDK to send logs to Kafka
Java SDK
Java SDK overview
Install TLS SDK for Java
Getting started
Use TLS SDK for Java to create basic resources
Use TLS SDK for Java to write logs
Use TLS SDK for Java to consume logs
Use TLS SDK for Java to query and analyze logs
Use TLS SDK for Java consumer groups to consume logs
Python SDK
Python SDK overview
Install TLS SDK for Python
Getting started
Use TLS SDK for Python consumer groups to consume logs
Android SDK
SDK for Android overview
Install TLS SDK for Android
Getting started
iOS SDK
SDK for iOS overview
Install TLS SDK for iOS
Getting started
Get SDK response information
Configure timeout and retry policies
C++ SDK
SDK for C++ Overview
Install TLS SDK for C++
Getting started
Get SDK response information
Configure timeout and retry policies
Node.js SDK
SDK for Node.js overview
Install TLS SDK for Node.js
Getting started
Browser JavaScript SDK
.NET SDK
.NET SDK overview
Install the .NET SDK
Quick start .NET SDK
Best practices
Data collection
Upload logs using Flume
Upload logs using Logstash
Enable LogCollector high precision time
Transmit data using Flink
Monitor LogCollector collection
Configure network connections for cross-region log collection
query and analysis
Query and analyze operations and maintenance logs
Query and analysis of JSON logs
Query and analysis of Nginx access logs
permission management
Use Security Token Service to access Torch Log Service
Set TLS access permissions through IAM
Enable cross-account access to TLS based on IAM roles
Consumption and delivery
Consume logs via ByteHouse
Consume logs using Spark Streaming
Consume logs using Flink
Synchronize TLS data to EMR Hive in real time
Visualization of Kafka protocol consumption metrics
Visualization
Create a line chart with double Y-axes
Alarm
Trigger alerts based on log keywords
Common methods for controlling the time window for sending alert notifications
Log-based JuiceFS observability best practices
FAQs
Query and analysis
Common errors in query and analysis
What are the usage scenarios of quotation marks in query and analysis statements?
How to query for phrases accurately?
How do I perform a fuzzy query on logs?
Why is the log time inconsistent with its generation time?
FAQ about query and analysis of JSON logs
How to improve the speed of query and analysis?
What can I do if the query results are inaccurate?
Data collection
The basic issues of LogCollector
Troubleshooting LogCollector operations and maintenance failures
How to troubleshoot abnormal log collection on the host machine?
How to troubleshoot abnormal log collection on the container?
Host group heartbeat issues on a host
Host group heartbeat issues on a container
Abnormal LogCollector status on a container
How should high load on the K8S API Server caused by a large number of ListWatch requests be handled?
Alarm
Alarm policy frequently asked questions
Frequently asked questions about alert notification channels
Frequently asked questions about alarm service logs
Frequently asked questions about alarm notification content
How to set up Feishu, DingTalk, and WeCom alert notifications
Resource Management
How do I view the log storage period?
How to delete projects and topics?
Why can't I delete the log topic?
IP address allowlist
What are the differences between Torch Log Service and Datasail?
Frequently asked questions about product billing
FAQ about scheduled SQL analysis
FAQ about API and SDK
Common trace storage issues
Documentation
Torch Log Service
User Guide
Data collection
LogCollector collection
LogCollector plugins
Add field plugin
Copy page
Download PDF
LogCollector plugins
Add field plugin
Copy page
Download PDF
Add field plugin
Last updated: 2025.12.05 15:26:14