ActionTrail supports multiple methods to query the details of events related to an AccessKey pair. You can use the AccessKey pair audit feature to query information such as Alibaba Cloud services accessed by using an AccessKey pair and related IP addresses. You can use the event query feature to query the details of the event records of an AccessKey pair. This topic describes how to query Alibaba Cloud services that are accessed by using an AccessKey pair and call records of the AccessKey pair. This topic also provides additional information about events related to an AccessKey pair.
Query Alibaba Cloud services that are accessed by using an AccessKey pair
You can query all Alibaba Cloud services that are accessed by using an AccessKey pair only after the AccessKey pair audit feature is enabled.
Data is updated at 1-hour intervals. As a result, query latency exists. We recommend that you do not change an AccessKey pair unless necessary.
Log on to the ActionTrail console.
In the left-side navigation pane, click AccessKey Pair Audit.
On the AccessKey Pair Audit page, enter the AccessKey ID that you want to query and click the icon to query information about the AccessKey pair. The information includes the Resource Access Management (RAM) user to which the AccessKey pair belongs, the Alibaba Cloud services that are accessed by using the AccessKey pair, and the time when the AccessKey pair was last called.
Perform the following operations based on your business requirements:
Query the call records of an AccessKey pair
You can query only the events that are supported by ActionTrail. For more information, see Services that work with ActionTrail.
Log on to the ActionTrail console.
In the left-side navigation pane, click Event Detail Query.
In the top navigation bar, select the region of the event that you want to query from the drop-down list.
On the Event Detail Query page, select AccessKey ID as the query condition and enter the AccessKey ID.
Specify a time range and click the icon.
Optional. If the advanced event query feature is enabled for your Alibaba Cloud account, choose in the ActionTrail console to query the call records of the AccessKey pair in all regions.
NoteThe advanced event query feature allows you to query only specific events.
You can query the call records of an AccessKey pair in simple query mode. In this case, enter the AccessKey ID that you want to query in the AccessKey ID field, specify a time range, and then click Run.
You can turn off the simple query mode, enter the event.userIdentity.accessKeyId:* conditional clause, specify a time range, and then click Run.
Additional information
You can query all Alibaba Cloud services that are accessed by using an AccessKey pair. You can query only events that are supported by ActionTrail. For more information, see Services that work with ActionTrail.
If the results of your query show that an Alibaba Cloud service is accessed by using an AccessKey pair but no information about the access is displayed in the event list, IP address list, or resource list or the time when the Alibaba Cloud service last was accessed does not match the actual access time, ActionTrail does not support the Alibaba Cloud service or event.
References
You can enable the advanced event query feature and use a system template to query the details of events related to an AccessKey pair. For more information, see Query events of an Alibaba Cloud account or an AccessKey pair.
You can configure query conditions to query events related to an AccessKey pair in SQL query mode. For more information, see Perform custom event queries.