Log delivery in Elastic Cloud Serverless
Log delivery lets you ship selected log types from any Elastic Cloud Serverless project to any Elastic Security Serverless or Elastic Observability Serverless project in your organization.
With log delivery, you can:
- Select source and destination projects in your organization.
- Apply ignore filters to exclude events you don't need delivered.
- Manage billing and usage by adjusting delivered volume and retention.
The source is the Serverless project that produces the logs. You configure log delivery here. Any project type (Elasticsearch Serverless, Elastic Security Serverless, or Elastic Observability Serverless) can be a source.
The destination is the Serverless project that receives and stores the delivered logs. You can choose multiple destinations for each log type. Destinations must be Elastic Security Serverless or Elastic Observability Serverless projects in the same organization.
You can use the same project as both source and destination. The destination can be in a different cloud provider region than the source, however, cross-region delivery can incur data transfer charges. Refer to Billing and usage.
Logs are encrypted while moving from your source project to the destination project(s) and while they are stored on the destination.
When configuring log delivery, you can apply ignore filters to exclude certain events from being delivered. For example, if you're setting up an audit trail log delivery and you don't need data on every role check, you could apply the Ignore routine user and role checks filter. Role check information will not be delivered to your selected destination project.
Ignore filters exclude matching events before delivery, reducing the volume of your delivery and the overall cost. If you don't choose any ignore filters, all events for your chosen log type will be delivered. This is the highest volume option and directly affects your Serverless bill.
Log delivery usage is metered. Cost is proportional to the volume of the delivery and retention of the data delivered, so you can control it by managing these parameters:
- Usage depends on the combination of source project, log type, and destination project you choose. Adjust these combinations to see which ones drive higher volume.
- Data transfer charges depend on the combination of source and destination projects. For example, same-project delivery does not incur transfer charges, but delivery to a different project in a different region does. Consider this in your configuration.
- Ignore filters exclude events before delivery. Use them to reduce the volume of delivered data.
- Retention of delivered data is billed on the destination project. Use AutoOps on this project to monitor your ingest rate and storage retained, and adjust accordingly.
For exact rates, refer to Elastic Security Serverless pricing and Elastic Observability Serverless pricing.
Audit trail is the first log type available for delivery. More log types are coming soon.