Embedding CLS Console

Last updated: 2021-10-25 16:15:26


    CLS allows you to embed the CLS console into an external system so you can conduct log search and analysis without logging in to Tencent Cloud console. This feature offers benefits as follows:

    • Quickly integrate CLS search and analysis capabilities into an external service system (e.g., for business maintenance or operation).
    • Easily share your log data with others without needing to manage additional Tencent Cloud sub-accounts.

    Sample code for an embedded page: cls-iframe-demo.

    See the figure below for an overview of this feature:


    1. Log in to the CAM console to create a CAM role with console login permissions. Set the role entity to root account, e.g. CompanyOpsRole. Grant the CAM role appropriate access permissions using policies, e.g. QcloudCLSReadOnlyAccess for read-only access. You can create a CAM role in 2 ways: using the console or using APIs.

      • Creating a CAM role using the console:

        1. Log in to the CAM console.
        2. Click Roles on the left sidebar to go to the roles list page.
        3. Select Create Role > Tencent Cloud Account to create a custom role.
        4. Select Current root account *, check *Allow the current role to access console, and click Next.

        If the option *Allow the current role to access console is not available, submit a ticket to apply for adding the role to the allowlist.

        1. Set access policies for the role, e.g., the read-only policy QcloudCLSReadOnlyAccess, and click Next.
        1. Enter the role name and click Done.

    • Creating a CAM role using APIs:
      For detailed directions, see CreateRole. Note that you need to enter 1 as the value of ConsoleLogin to allow the role to log in to the console.
      Sample request:
    1. Obtain the access key of the current user. For more information, see Root Account Access Key.


    1. Log in to the web server outside Tencent Cloud.

    2. The external web server assigns you the pre-created role created in Prerequisite 1 based on your identity, e.g. CompanyOpsRole.

    3. The web server accesses the Tencent Cloud STS service based on the role name and uses the access key obtained in Prerequisite 2 to call the AssumeRole API to apply for a temporary key of CompanyOpsRole.

    4. Call the AssumeRole API to get the temporary key of CompanyOpsRole.

    5. Generate a login signature using the temporary key with the steps as shown below:

      1. Sorting parameters
        Sort parameters to be signed listed below in ascending alphabetical or numerical order. That is, sort the parameters by their first letters, then by their second letters if their first letters are the same, and so on. You can do this with the aid of sorting functions in programming languages, such as the ksort function in PHP.

        Parameter Required Type Description
        action Yes String Action; fixed as `roleLogin`
        timestamp Yes Int Current timestamp
        nonce Yes Int Random integer. Value range: 10000-100000000
        secretId Yes String Temporary AK returned by STS
      2. Formatting parameters
        Combine the above sorted parameters into the form of "parameter name=parameter value". Example:

      3. Constructing a signature string
        Construct a signature string in the format of “request method + request CVM + request path + ? + request string”.

        Parameter Required Description
        Request CVM and path Yes Fixed as cloud.tencent.com/login/roleAccessCallback
        Request method Yes GET or POST

        Sample signature string

      4. Generating a signature string
        Currently, you can sign a string using HMAC-SHA1 or HMAC-SHA256. The sample code in PHP is as follows:

        $secretKey = 'Gu5***1qA';
        $srcStr    = 'GETcloud.tencent.com/login/roleAccessCallback?action=roleLogin&nonce=67439&secretId=&timestamp=1484793352';
        $signStr   = base64_encode(hash_hmac('sha1', $srcStr, $secretKey, true));
        echo $signStr;

      Sample code for PHP

       $secretId  = "AKI***";            //Temporary AK returned by STS
       $secretKey = "Gu5***PLE";         //Temporary SecretKey returned by STS
       $token     = "ADE***fds";         //Security Token returned by STS
       $param["nonce"]     = 11886;      //rand(10000,100000000);
       $param["timestamp"] = 1465185768; //time();
       $param["secretId"]  = $secretId;
       $param["action"]    = "roleLogin";
       $signStr = "GETcloud.tencent.com/login/roleAccessCallback?";
       foreach ( $param as $key => $value ) {
           $signStr = $signStr . $key . "=" . $value . "&";
       $signStr   = substr($signStr, 0, -1);
       $signature = base64_encode(hash_hmac("sha1", $signStr, $secretKey, true));
       echo $signature.PHP_EOL;
    6. Combine your login information and destination page URL into a login URL.

      1. Get the CLS console search analysis page URL.

      Parameters in the CLS console search analysis page URL:

      Parameter Required Type Description
      region Yes String Region abbreviation, e.g., ap-shanghai for Shanghai region. For other available region abbreviations, see Available Regions
      logset_id Yes String Logset ID
      topic_id Yes String Log topic ID
      time No String Time range for log search. Format example:
      query No String Keyword search syntax. Reserved URL characters (if any) in keywords must be URL encoded
      hideWidget No Boolean Indicates whether to hide the Smart Customer Service icon. `true`: Yes; `false`: No (default)
      hideTopNav No Boolean Indicates whether to hide the top navigation bar in the Tencent Cloud console. `true`: Yes; `false`: No (default)
      hideLeftNav No Boolean Indicates whether to hide the left sidebar in the Tencent Cloud console. `true`: Yes; `false`: No (default)
      hideHeader No Boolean Indicates whether to hide the top navigation bar on the CLS page (title and region options). `true`: Yes; `false`: No (default)
      hideTopTips No Boolean Indicates whether to hide the tips on the CLS page. `true`: Yes; `false`: No (default)
      hideRegion No Boolean Indicates whether to hide region options at the top of the CLS page. `true`: Yes; `false`: No (default)
      hideLogsetSelect No Boolean Indicates whether to hide logset options on the CLS page. `true`: Yes; `false`: No (default)
      hideTopicSelect No Boolean Indicates whether to hide log topic options on the CLS page. `true`: Yes; `false`: No (default)
      2. Splice your login information and destination page URL into a login URL. The parameter values should be URL-encoded.
      ?algorithm=<encryption algorithm for signing; currently only supports SHA1 (used by default) and SHA256
      &secretId=<secretId for signing>
      &token=<Temporary key token>
      &nonce=<nonce for signing>
      &timestamp=<timestamp for signing>
      &signature=<signature string>
      &s_url=<destination URL after login>
    7. Use the final URL to access the embedded CLS page of the Tencent Cloud console. The sample below is a URL to the CLS search analysis page: