By default, ActionTrail stores only the events that were generated in the last 90 days within your Alibaba Cloud account. However, Multi-Level Protection Scheme (MLPS) 2.0 stipulates that events must be retained for 180 days or longer. Therefore, you can create a trail and a historical event delivery task to store the required events for a long period. Otherwise, you cannot query the events that were generated more than 90 days ago.
Prerequisites
Background information
A trail can deliver only the events that are generated after the trail is created. Therefore, you must create a historical event delivery task to deliver the events that were generated in the last 90 days before your trail is created. This ensures that all the events required for auditing are stored.
A historical event delivery task applies only to the events that were generated in the time range from 90 days before the current time to 5 minutes after the trail that is associated with the task took effect. For example, you have created Trail A 40 days before you create a historical event delivery task that is associated with Trail A. In this case, the task delivers only the events that were generated in the last 50 days before Trail A was created.
- A historical event delivery task delivers only the historical events that are tracked by the associated single-account trail to the Log Service Logstore that you specify.
- Only one historical event delivery task can be running at a time within an Alibaba Cloud account.
Step 1: Create a single-account trail to deliver events to Log Service
Step 2: Create a historical event delivery task
Step 3: Query the required events (Optional)
- In the left-side navigation pane, click Trails.
- In the top navigation bar, select the region where the created single-account trail and historical event delivery task reside.
- On the Trails page, find the trail that you created, move the pointer over the
icon in the Storage Service column, and then click the name of the Log Service Logstore.
- In the upper-right corner of the page that appears, click 15 Minutes(Relative) to specify a time range for the query.
- Click Search & Analyze to query events.