After an enterprise creates a resource directory, the master account can create multi-account trails in the ActionTrail console. A multi-account trail can deliver the operations logs of all member accounts in a resource directory to the specified Object Storage Service (OSS) bucket or Log Service Logstore.

Note The multi-account trail feature is currently under invitational preview. To use this feature, submit a ticket or contact the service manager to add your account to the whitelist.

The following figure shows how a multi-account trail works with a resource directory.

Multi-account trail

Terms

Term Description
Master account

The master account is the account that is used to enable the Resource Directory feature, and is a super administrator of the resource directory. The master account has permissions to manage resource directories that are created by the master account and to manage member accounts. Only the master account that has passed real-name verification of enterprises can enable Resource Directory. A resource directory has only one master account.

Member account

Member account is a type of Alibaba Cloud accounts in Resource Directory. A member account is a resource container used to group resources. A member account can be a system or an application. The resources of different member accounts are isolated.

You can use the master account to invite a member account to join a resource directory or create a member account in a resource directory.

Multi-account trail A multi-account trail is a trail created in the ActionTrail console by using a master account, with Apply Trail to All Member Accounts set to Yes. A multi-account trail delivers the operations logs of all member accounts to the specified OSS bucket or Log Service Logstore.
Single-account trail A single-account trail is a trail created in the ActionTrail console by using an Alibaba Cloud account to track and record the operations of the current account.

Differences between multi-account and single-account trails

Trail type Created by Logs to deliver Query method Maximum number of trails allowed
Single-account trail Alibaba Cloud account Operations logs of the current account
  • ActionTrail console
  • LookupEvents operation
  • OSS console
  • Log Service console
Five in each region
Multi-account trail Master account Operations logs of all member accounts
  • Master account:
    • ActionTrail console
    • LookupEvents operation
  • Member account:
    • OSS console
    • Log Service console
One in each region

Changes of member accounts in a resource directory

When a member account in a resource directory changes, ActionTrail performs the following operations:

  • After the master account invites a member account to join the resource directory or creates a member account in the resource directory, the new member account can view multi-account trails in the trail list. The operations logs of the new member account will be automatically delivered to the specified OSS bucket or Log Service Logstore.
  • After a member account is removed from the resource directory, the member account cannot view multi-account trails. The operations logs of the member account will no longer be delivered to the specified OSS bucket or Log Service Logstore. However, the logs that have been delivered will not be automatically deleted.
  • The change of the resource directory to which a member account belongs does not affect the delivery of operations logs.