ActionTrail provides several ways to find event details for an access key pair. Use the AccessKey Pair Audit feature to identify which cloud services were accessed and from which IP addresses, or use Event Query to look up detailed event records.
Query cloud services accessed by an access key pair
-
AccessKey Pair Audit covers all cloud services accessed by a specific access key pair since the feature was launched.
-
Data latency can be up to several hours, so use caution when making changes to an access key pair based on this information.
-
Log on to the ActionTrail console.
-
In the left-side navigation pane, click AccessKey Pair Audit.
-
On the AccessKey Pair Audit page, enter an AccessKey ID and click the
icon. You can then view details about the access key pair, including the associated RAM user, the cloud services it has accessed, and the last used time.The query results also show the account ID and RAM user ID. In the Accessed Cloud Services table, each entry links to the Event List, IP Address List, and Resource List for further investigation.
-
As needed, review the Event List, IP Address List, and Resource List.
Query detailed call records for an access key pair
Specific events for an access key pair can be queried only for the cloud services and events that ActionTrail supports. For more information, see Cloud services and events supported by ActionTrail.
-
Log on to the ActionTrail console.
-
In the left-side navigation pane, click Event Detail Query.
-
In the top navigation bar, select the region where you want to query events.
-
On the Event Detail Query page, set the filter condition to AccessKey ID and enter the AccessKey ID.
-
Set the time range for the query and click the
icon. -
(Optional) If Advanced Event Query is enabled for your account, you can select Events > Advanced Query in the ActionTrail console to query the call records for the access key pair across all regions.
Note-
Advanced Event Query supports only certain detailed events.
-
You can use simple query mode, set the filter condition to AccessKey ID, enter the ID, select a time range, and then click Run.
-
You can also turn off simple query mode, enter the condition statement event.userIdentity.accessKeyId:*, select a time range, and then click Run.
-
Notes
ActionTrail can identify all cloud services accessed by an access key pair. However, specific events can be queried only for supported cloud services and event types. For more information, see Cloud services and events supported by ActionTrail.
If a query shows that an access key pair accessed a cloud service but the Event List, IP Address List, or Resource List is empty or shows a mismatched last access time, ActionTrail does not yet support that cloud service or event type.
References
-
To query event details for an access key pair with a system template, enable Advanced Event Query. For more information, see Query events for an Alibaba Cloud account or access key pair.
-
To find events related to an access key pair with SQL query mode, see Custom event queries.