API standards and multilingual preset SDKs
The OpenAPI of this product (Actiontrail/2020-07-06) uses the RPC signature style. We have encapsulated SDKs for common programming languages for developers. Developers can download the SDK to directly call this product's OpenAPI without worrying about technical details. If the existing SDK does not meet your needs, you can use the signature mechanism for self-signing integration. Since the details of self-signing are very complex, it may take around 5 business days. Therefore, we recommend joining our DingTalk service group (147535001692) and conducting signature integration under expert guidance.
Before using the API, you need to prepare your identity account and access key (AccessKey) to effectively access the API through client tools (such as SDK and CLI). For details, see Obtain an AccessKey.
Custom signature scenarios
If your business scenario has special requirements and you need to integrate the API through self-signing, we recommend consulting our technical support team first (DingTalk service group: 147535001692) to obtain professional guidance and ensure efficient integration.
Account and security preparation
Alibaba Cloud accounts have full administrative permissions over all resources. Once an AccessKey is compromised, all associated resources will be at risk of unauthorized access. To ensure security, it is recommended to create a RAM user with only API access permissions and configure its AccessKey, while configuring RAM policies based on the principle of least privilege (PoLP). Use the Alibaba Cloud account only in specific scenarios where Alibaba Cloud account permissions are explicitly required.
Region
|
API |
Title |
Description |
| DescribeRegions | DescribeRegions | Queries the Alibaba Cloud regions that are supported by ActionTrail. |
Trail
|
API |
Title |
Description |
| CreateTrail | CreateTrail | Creates a trail to deliver events to a destination for long-term storage and analysis, such as an Object Storage Service (OSS) bucket, a Simple Log Service (SLS) Logstore, or a MaxCompute project. |
| DeleteTrail | DeleteTrail | Deletes a trail. |
| StartLogging | StartLogging | Enables a trail to start delivering ActionTrail events to Object Storage Service (OSS), Simple Log Service (SLS), or MaxCompute. |
| UpdateTrail | UpdateTrail | Updates the configurations of a trail. |
| StopLogging | StopLogging | Disables a trail to stop delivering ActionTrail events to Object Storage Service (OSS), Simple Log Service (SLS), or MaxCompute. |
| GetTrailStatus | GetTrailStatus | Queries the status of a trail. |
| DescribeTrails | DescribeTrails | Queries created trails. |
| DescribeUserTrailCount | DescribeUserTrailCount | Queries the number of enabled trails, including organization trails. |
| DescribeTrailDeliveryMetricData | DescribeTrailDeliveryMetricData | Retrieves data for delivery monitoring metrics. |
Management event
|
API |
Title |
Description |
| LookupEvents | LookupEvents | Queries detailed historical events. |
Data backfill
|
API |
Title |
Description |
| CreateDeliveryHistoryJob | CreateDeliveryHistoryJob | Creates a data backfill task. |
| DeleteDeliveryHistoryJob | DeleteDeliveryHistoryJob | Deletes a data backfill task. |
| ListDeliveryHistoryJobs | ListDeliveryHistoryJobs | Queries a list of data backfill tasks. |
| GetDeliveryHistoryJob | GetDeliveryHistoryJob | Queries the details of a data backfill task. |
AccessKey audit
|
API |
Title |
Description |
| GetAccessKeyLastUsedEvents | GetAccessKeyLastUsedEvents | Queries the most recent events associated with a specified AccessKey pair, including the event name, source, timestamp, and details. |
| GetAccessKeyLastUsedInfo | GetAccessKeyLastUsedInfo | Queries the most recent usage record of a specified AccessKey pair. |
| GetAccessKeyLastUsedIps | GetAccessKeyLastUsedIps | Queries the IP addresses most recently used by a specified AccessKey pair. |
| GetAccessKeyLastUsedProducts | GetAccessKeyLastUsedProducts | Queries the Alibaba Cloud services most recently accessed by a specified AccessKey pair. |
| GetAccessKeyLastUsedResources | GetAccessKeyLastUsedResources | Queries the resources most recently used by a specified AccessKey pair. |
Data event selector
|
API |
Title |
Description |
| ListDataEventSelectors | ListDataEventSelectors | Queries all data event selectors. |
| GetDataEventSelector | GetDataEventSelector | Queries the details about the data event selector for a specified trail. |
| PutDataEventSelector | PutDataEventSelector | Creates or configures a data event selector. A trail must exist before you create a data event selector. If a trail does not exist, you can call the CreateTrail operation to create one. |
| DeleteDataEventSelector | DeleteDataEventSelector | Deletes the data event selector for a specified trail. |
Event insight
|
API |
Title |
Description |
| EnableInsight | EnableInsight | Enables the Insights feature. |
| DisableInsight | DisableInsight | Disables a specific type of Insights event. |
| GetInsightTypes | GetInsightTypes | Queries all enabled types of Insights events. |
| GetInsightSelectors | GetInsightSelectors | Queries the Insights event types to deliver for a trail. |
| GetInsightsEventsCount | GetInsightsEventsCount | Queries the number of Insights events for the current account. |
| PutInsightSelectors | PutInsightSelectors | Specifies the types of Insights events to deliver for a trail. |
| LookupInsightEvents | LookupInsightEvents | Queries Insights events. |
Other
|
API |
Title |
Description |
| UpdateAdvancedQueryTemplate | UpdateAdvancedQueryTemplate | Updates an advanced query template. |
| GetGlobalEventsStorageRegion | GetGlobalEventsStorageRegion | Queries the region where global events are stored. |
| CreateAdvancedQueryTemplate | CreateAdvancedQueryTemplate | Creates an advanced query template. |
| DeleteAdvancedQueryTemplate | DeleteAdvancedQueryTemplate | Deletes an advanced query template. |
| DescribeAdvancedQueryTemplate | DescribeAdvancedQueryTemplate | Queries advanced query templates. |
| DescribeUserAlertCount | DescribeUserAlertCount | Queries the number of daily alerts within a specific time range. |
| DescribeUserLogCount | DescribeUserLogCount | Queries the number of daily logs within a specific time range. |
| GetAdvancedQueryTemplate | Retrieve a single advanced template | Retrieves information about a single advanced template. |
| DeleteAdvancedQueryHistory | DeleteAdvancedQueryHistory | Deletes an advanced query record. |
| CreateAdvancedQueryHistory | CreateAdvancedQueryHistory | Creates an advanced query record. It lets you save custom conditional statements for reuse. |
| DescribeAdvancedQueryHistory | DescribeAdvancedQueryHistory | Queries all advanced query records. |
| DescribeResourceLifeCycleEvents | DescribeResourceLifeCycleEvents | Queries the lifecycle events of a specified resource. |
| DescribeScenes | DescribeScenes | Queries all advanced query scenarios. |
| DescribeSearchTemplates | DescribeSearchTemplates | Queries advanced query templates for a specified scenario. |
| ListDataEventServices | ListDataEventServices | Queries the services that support data events and the names of these events. |
| GetGovernanceMetrics | GetGovernanceMetrics | Queries the governance metrics of ActionTrail. |
Others
|
API |
Title |
Description |
| UpdateGlobalEventsStorageRegion | UpdateGlobalEventsStorageRegion | Specifies the region where you want to store global events. |