ActionTrail

Updated at: 2024-08-10 15:20

ActionTrail monitors and records the events within your Alibaba Cloud account. You can collect the events to Simple Log Service and use the new version of Log Audit Service to perform the following operations: behavior analysis, security analysis, resource change tracing, and behavior compliance audit. This topic describes how to collect ActionTrail logs to the new version of Log Audit Service.

Background information

  • ActionTrail monitors and records the events within your Alibaba Cloud account. The events include your access to and use of cloud services in the Alibaba Cloud Management Console or by using APIs and SDKs. By default, ActionTrail tracks and records events that are generated within the previous 90 days. You can query the events. For more information, see What is ActionTrail?

  • The new version of Log Audit Service is based on Alibaba Cloud Simple Log Service. You can use multiple projects to manage logs. You can aggregate, query, and analyze cloud service logs in a centralized manner, and you can process logs to meet region-specific data compliance requirements. This way, you can manage data in a legal and orderly manner. For more information, see Overview of Log Audit Service (new version).

Overview

The following figure shows the flowchart of collecting ActionTrail logs to the new version of Log Audit Service. The application supports multiple cloud services.

image

Prerequisites

1. Associate a project

  1. Log on to the Simple Log Service console and create a project. For this example, create a project named sample-production-cn-hangzhou in the China (Hangzhou) region.

  2. In the Log Application section, click the Audit & Security tab. Then, click Log Audit Service (New Version).

    image

  3. On the Log Audit (New Version) page, click Associate Project. In the Associate Project dialog box, configure the parameters and click Confirm.

    Note

    ActionTrail logs are collected to the project that you associate with the new version of Log Audit Service.

    image

  4. On the Log Audit (New Version) page, click the associated project.

    image

  5. On the Cloud Services tab, click Enable Now for ActionTrail.

    image

2. Create a trail

  1. In the Go to ActionTrail Console Create Trail panel, read the requirements for creating a trail. Then, click ActionTrail Console.

    image

  2. In the ActionTrail console, configure the parameters in the Basic Information and Event Delivery sections. The following figure shows sample configurations.

    image

  3. After you create the trail, view the details of the trail. A Logstore named actiontrail_sample-production-actiontrail is automatically created.

    Note

    ActionTrail automatically creates a Logstore named actiontrail_<Trail name>.

    image

3. Query and analyze logs

  1. On the Log Audit (New Version) page, click the project that you want to manage. On the Cloud Services tab of the page that appears, click View for ActionTrail in the Policy-enabled Cloud Services section.

    image

  2. On the ActionTrail Logs tab of the Query and Analysis page, query and analyze logs.

    image

References

  • For more information about how to enable indexing for a Logstore, see Create indexes. For more information about how to query and analyze logs in a Logstore, see Query and analyze logs.

  • In this topic, ActionTrail logs are used only as an example. For more information about the log types, default project and Logstore names, and billing details of other supported cloud services, see Usage notes of cloud service configuration.

  • On this page (1)
  • Background information
  • Overview
  • Prerequisites
  • 1. Associate a project
  • 2. Create a trail
  • 3. Query and analyze logs
  • References
Feedback