The Alibaba Cloud account is the owner of Alibaba Cloud resources. If the Alibaba Cloud account is disclosed, your resources are at risk. You can create a trail in the ActionTrail console to deliver events to Log Service. Then, you can configure alert rules to monitor the use of your Alibaba Cloud account.
Prerequisites
If Log Service is not activated, log on to the Log Service console and activate the service by following the on-screen instructions.
Step 1: Create a trail
This section describes how to create a single-account trail to deliver events to Log Service.
Step 2: Query events and configure an alert rule to monitor the use of an Alibaba Cloud account in Log Service
- In the left-side navigation pane of the ActionTrail console, click Trails.
- On the Trails page, find the trail that you created, move the pointer over the
icon in the Storage Service column, and then click the name of the Log Service Logstore.
- In the upper-right corner of the page that appears, click 15 Minutes(Relative) to specify a time range for the query.
- Enter
event.userIdentity.type:"root-account"| select count(1) as use_root
in the search box and click Search & Analyze. - Click Save Search or Save as Alert.
- Save the query: Click Save Search in the upper-right corner. In the Saved Search Details panel, set the Saved Search Name parameter and click OK.
Note After you save the query, you can select it in the Log Service console to initiate the query.
For more information, see Saved search.
- Configure an alert rule based on the query: Choose Alert Monitoring Rule panel, set the parameters and click OK.
For more information, see Configure an alert rule.
Note After you configure the alert rule, you can receive an alert notification when the alert is triggered. For example, Log Service checks the use of your Alibaba Cloud account every 5 minutes based on the alert rule that is shown in the preceding figure. If your Alibaba Cloud account is used in the last 5 minutes, Log Service generates an alert.
in the upper-right corner. In the
- Save the query: Click Save Search in the upper-right corner. In the Saved Search Details panel, set the Saved Search Name parameter and click OK.
Result
You can manage the saved queries and alert rules in the Log Service console.
