This topic describes how to enable the SQL audit and analysis feature in the Distributed Relational Database Service (DRDS) console.
- Log on to the DRDS console.
- In the upper-left corner of the page, select the region where the instance resides.
- On the Instance list name page, click the name of the instance.
- In the left-side navigation pane, choose .
- Authorize DRDS as prompted to assume the AliyunDRDSDefaultRole role to access Log Service.Note
- This operation is required only when you enable the SQL audit and analysis feature for the first time. You must complete the authorization by using your Alibaba Cloud account.
- If you use a RAM user to log on to DRDS, you must grant required permissions to the RAM user. For more information, see RAM user authorization.
- To ensure that DRDS SQL audit logs can be sent to Log Service, do not delete the RAM role.
- Enable the SQL audit and analysis feature.
- Select the database, and then turn on the switch next to the database or turn on the
SQL Audit Log Status of Current Database switch.
- Optional:Import historical data.
By default, only the logs that are generated after the SQL audit and analysis feature is enabled are sent to Log Service. If you want to analyze logs that are generated before the SQL audit and analysis feature is enabled, you can import historical data. To do so, you can turn on the Import Historical Data or Not switch in the Log Storage Period dialog box. Then, set the Trace Start Time and Trace End Time parameters. You can import up to seven days of historical data.
You can view the log import progress in the Task Progress dialog box in the upper-right corner of the current page.
- Click Enable.
- Select the database, and then turn on the switch next to the database or turn on the SQL Audit Log Status of Current Database switch.