This topic describes the basic terms that are involved in ActionTrail. The information helps you better understand and use this service.
A management account is used to enable a resource directory and is the super administrator of the resource directory. The management account has all administrative permissions on the resource directory and the member accounts in the resource directory. Only an Alibaba Cloud account that has passed enterprise real-name verification can be used as a management account. Each resource directory has only one management account.
A member account serves as a container for resources and an organizational unit in the resource directory involved. A member account indicates a project or an application. The resources of different member accounts are isolated. You can use a management account to authorize RAM users, user groups, or roles to access the resources of member accounts.
You can use a management account to invite a member account to join the resource directory involved or create a member account in the resource directory.
|user-initiated event||A user-initiated event is a record that is generated when you use the Alibaba Cloud Management Console, API operations, or developer tools to access and manage services on Alibaba Cloud. A user-initiated event records information about an operation that you perform. The information includes the operation time, username, resource, operation type, operation result, and source IP address. User-initiated events can be classified into management events and insight events based on event sources.|
|management event||A management event is a record that is generated when you perform a control plane operation but not a data plane operation to manage resources on Alibaba Cloud. For example, a management event is generated when you create or delete an ApsaraDB RDS instance or an Object Storage Service (OSS) bucket. However, no management events are generated when you perform operations on the tables in an ApsaraDB RDS instance or the objects in an OSS bucket.|
|insight event||An insight event is a record that indicates an exception that is identified based on the analysis of management events. This helps you identify unusual operations that are recorded in management events. Only insight events of the IPInsight type are supported. After you enable the insight event feature for a trail, ActionTrail determines the usual IP addresses based on the historical management events recorded by the trail. If an operation is performed from an unfamiliar IP address that is not in the whitelist, ActionTrail compares the IP address with the usual IP addresses and determines whether it is unusual. If an IP address is considered unusual, an IPInsight event is generated to inform you of the exception.|
|global service||A global service applies to all regions of Alibaba Cloud, such as Resource Access Management (RAM). Global services generate global events.|
|global event||A global event is a record of a global service. On the Event Detail Query page in the ActionTrail console, you can select a region to view all the global events. After you create a trail to deliver events to a specified OSS bucket, global events are recorded in the same directory as the events that occur in the home region of the trail.|
|home region||A home region is the region where a trail is created.|
|trail||A trail is created to deliver events to a specified OSS bucket or Log Service Logstore for storage and further analysis. Trails are divided into the following categories based on the creator, applicable scope, and delivered content: single-account trails, multi-account trails, and trails for the Inner-ActionTrail feature.|
|single-account trail||A single-account trail is a trail that is created to track and record the events of the Alibaba Cloud account that is used to create the trail.|
|multi-account trail||A multi-account trail is a trail that is created by using a management account to track and record the events of all member accounts. A multi-account trail can deliver the events of all member accounts in a resource directory to a specified OSS bucket or Log Service Logstore.|
|Alibaba Cloud-initiated event||An Alibaba Cloud-initiated event is a record that is generated when the Alibaba Cloud O&M team maintains services for you. You can create a trail for the Inner-ActionTrail feature to deliver Alibaba Cloud-initiated events to a specified storage object.|
|trail for the Inner-ActionTrail feature||A trail for the Inner-ActionTrail feature is a trail that is created by using an Alibaba Cloud account to deliver Alibaba Cloud-initiated events to a specified storage object.|
|shadow trail||A shadow trail is a trail that ActionTrail creates by replicating the configurations of a trail that you create to track events in multiple regions. ActionTrail creates a shadow trail in each of the regions to track and record the events in these regions.|