All Products
Search
Document Center

ActionTrail:Audit events for Anti-DDoS Origin

Last Updated:Aug 20, 2026

Anti-DDoS Origin is integrated with ActionTrail. You can query management events that are generated by user operations on Anti-DDoS Origin. ActionTrail can deliver these events to a Logstore in Simple Log Service (SLS) or a bucket in Object Storage Service (OSS) for real-time auditing and issue analysis.

ActionTrail records management events that are generated when users perform operations on cloud resources using methods such as OpenAPI or the console. The following table lists the Anti-DDoS Origin management events that you can query in ActionTrail. Descriptions for some events will be added later.

Event Name

Event Definition

AddCcBlackWhiteIpList

Create a rule for a blacklist or whitelist.

AddIp

Add the IP address of a protected object to an Anti-DDoS package.

AttachCcPolicyIp

Attach a CC policy to an IP address or an asset group.

CheckAccessLogAuth

Check the authorization information for access logs.

CheckGrant

Check the authorization status of the Anti-DDoS package service.

ConfigSchedruleOnDemand

Modify the scheduling rule for an on-demand instance.

Create

Purchase a product from the buy page.

CreateCcPolicy

Create a policy.

CreateCcPolicyL4Rule

Create a Layer 4 rule.

CreateSchedruleOnDemand

Create a scheduling rule for an on-demand instance.

CretateIpForward

Create an IP forward.

DelelteCcBlackWhiteIpList

Delete a blacklist or whitelist.

DeleteBlackhole

Deactivate blackhole filtering for a protected IP address.

DeleteCcPolicy

Delete a policy.

DeleteCcPolicyL4Rule

Delete a Layer 4 rule from a CC policy.

DeleteIp

Remove a protected IP address from an Anti-DDoS package.

DeleteIpForward

Delete an IP forward.

DescribeCcBlackWhiteIpList

Query a blacklist or whitelist.

DescribeCcPolicy

Query the details of a policy.

DescribeCcPolicyL4RuleList

Query the Layer 4 rules of a CC policy.

DescribeCcRule

Query the details of a rule.

DescribeDdosEvent

View DDoS events on a specified Anti-DDoS package.

DescribeEffectiveBlackWhiteIpCount

Query the number of effective blacklists and whitelists.

DescribeEffectiveBlackWhiteIpList

Query the effective blacklists and whitelists.

DescribeEffectivePolicy

Query the effective policies.

DescribeExcpetionCount

Query abnormal information about an Anti-DDoS package.

DescribeInstanceList

Query the details of Anti-DDoS package instances.

DescribeInstanceSpecs

Query the specifications of an Anti-DDoS package.

DescribeIpForwardList

Query the IP forward list.

DescribeIpListThreshold

Query the thresholds for a list of IP addresses in a batch.

DescribeOnDemandDdosEvent

Query the DDoS event records on an on-demand Anti-DDoS IP address.

DescribeOnDemandInstance

Query the information about an on-demand instance.

DescribeOnDemandInstanceStatus

Query the details of an on-demand instance.

DescribeOpEntities

Query the user's operation logs.

DescribePack

Query an Anti-DDoS package.

DescribePackIpList

Query the list of protected IP addresses in an Anti-DDoS package.

DescribePackList

Get the list of packages.

DescribePackPaidTraffic

Query the details of paid traffic.

DescribeRegions

Query available Alibaba Cloud regions.

DescribeResourcePackInstances

Query information about Anti-DDoS data transfer plans.

DescribeResourcePackStatistics

Query the statistics of an Anti-DDoS data transfer plan.

DescribeResourcePackUsage

Query the usage details of an Anti-DDoS data transfer plan.

DescribeTopTraffic

You can query within a specific time range.

DescribeTraffic

View the traffic on a specified Anti-DDoS package.

DettachCcPolicyIp

Detach a CC policy from an IP address.

GetSlsOpenStatus

Get the activation status of SLS.

ListCcPolicy

Query CC policies.

ListCcPolicyIp

Query the attachments between IP addresses and policies.

ListOpenedAccessLogInstances

List instances for which access logs are enabled.

ListTagKeys

Query all tags.

ListTagResources

Query the relationships between resources (Anti-DDoS Origin instances) and tags.

Modify

Upgrade or downgrade a product from the buy page.

ModifyCcBlackListIpExpireTime

Update the expiration time for an IP address in a blacklist.

ModifyCcPolicy

Modify a policy name.

ModifyCcPolicyL4Rule

Modify a Layer 4 rule of a CC policy.

ModifyCcRule

Modify a CC rule.

ModifyIpForwardStatus

Modify the status of an IP forward.

ModifyOnDemaondDefenseStatus

Modify the protection status of an on-demand instance.

ModifyRemark

Modify the remarks for an Anti-DDoS package.

QuerySchedruleOnDemand

Query the scheduling rule of an on-demand instance.

Release

Release an instance or other resources.

ReleaseInstance

Release an instance.

Renew

Renew an instance or a resource plan.

SetInstanceModeOnDemand

Set the scheduling pattern for an on-demand instance.

TagResources

Attach tags to specified resources (Anti-DDoS Origin instances).

UntagResources

Remove tags from specified resources (Anti-DDoS Origin instances).

AddDefensePolicyIpSet

N/A

AttachDefensePolicyIp

N/A

CheckAccessLogOpenable

N/A

CloseAccessLog

N/A

CreateDefensePolicy

N/A

CreateDefensePolicyFingerprint

N/A

CreateDefensePolicyPortRule

N/A

CreateIndustry

N/A

CreateInstances

N/A

DeleteDefensePolicy

N/A

DeleteDefensePolicyFingerprint

N/A

DeleteDefensePolicyPortRule

N/A

DescribeAttackDstPort

N/A

DescribeAttackEvtList

N/A

DescribeAttackingEvtList

N/A

DescribeAttackingIpCount

N/A

DescribeAttackSrcArea

N/A

DescribeAttackSrcIp

N/A

DescribeAttackSrcIsp

N/A

DescribeAttackSrcPort

N/A

DescribeAttackSummaryByDay

N/A

DescribeAttackType

N/A

DescribeBlackHole

N/A

DescribeDefensePolicyIpSet

N/A

DescribeEvtSummaryByDay

N/A

DescribeEvtTopBiz

N/A

DescribeEvtTopIp

N/A

DescribeEvtUserSummary

N/A

DescribeHistoryMaxTraffic

N/A

DescribeIndustry

N/A

DescribeIndustryList

N/A

DescribeIpProtectCnt

N/A

DescribeMaxTraffic

N/A

DescribeNearSourceMitigationSpec

N/A

DescribePrdUserSummary

N/A

DescribeTopTrafficIP

N/A

DescribeTrafficFlow

N/A

DetachDefensePolicyIp

N/A

DisabledNearSourceMitigation

N/A

EnabledNearSourceMitigation

N/A

GetSlsLogstoreInfo

N/A

ListDefensePolicies

N/A

ListDefensePolicyFingerprint

N/A

ListDefensePolicyIps

N/A

ListDefensePolicyPortRules

N/A

ListNearSourceMitigation

N/A

ModifyBlackholeStatus

N/A

ModifyDefensePolicy

N/A

ModifyDefensePolicyFingerprint

N/A

ModifyDefensePolicyIpSet

N/A

ModifyDefensePolicyPortRule

N/A

MoveResourceGroup

N/A

OpenAccessLog

N/A

ReleaseAccessLog

N/A

RemoveDefensePolicyIpSet

N/A