ActionTrail stores events for 90 days by default. To retain events longer or perform advanced analysis, create a trail to deliver events to OSS, SLS, or MaxCompute for long-term storage.
Prerequisites
-
Object Storage Service (OSS) is activated. Activate OSS.
-
Log Service (SLS) is activated.
The first time you use Log Service (SLS), you must log on to the Log Service console and activate the service as prompted.
-
MaxCompute is activated. Activate MaxCompute.
Use cases
Without a trail, events older than 90 days are inaccessible. Create a trail to address these scenarios:
-
Scenario 1: Retain events for 180 days or longer
To meet compliance requirements such as MLPS 2.0 (180-day minimum retention), deliver events to OSS, SLS, or MaxCompute. Events are stored permanently by default. To limit retention to 180 days, adjust settings in Modify the event retention period in OSS or Modify the event retention period in SLS.
-
Scenario 2: Analyze and create alerts for sensitive operations
Deliver events to SLS and configure alerts to detect sensitive operations such as order creation or resource deletion.
-
Scenario 3: Analyze events with MaxCompute
For advanced analytics beyond SLS capabilities, deliver events to SLS and export them to MaxCompute for distributed big data processing.
-
Scenario 4: Cost-effectively analyze and permanently store events
Service costs rank SLS > MaxCompute > OSS. For cost-effective real-time analysis with permanent storage, deliver events to SLS with a limited retention period, then periodically export to MaxCompute or OSS for archival.
Scenario 1: Retain events for 180 days or longer
-
Log on to the ActionTrail console.
-
In the left navigation bar, click > Trail.
-
In the top navigation bar, select the region where you want to create the trail.
-
On the Trail page, click Create Trail.
-
On the Create Trail page, configure the parameters for the trail.
-
In the Basic Information section, configure the trail parameters.
Parameter
Description
Trail Name
Must be unique within your Alibaba Cloud account.
Trail Configuration
Set All Events to All Events.
-
In the Event Delivery Settings section, select a destination service.
-
Select Delivery to Log Service, and then select Delivery to Current Account.
-
New Log Service Project: Select a Logstore Region and enter a Project Name.
-
Existing Log Service Project: Select a Logstore Region and a Project Name.
-
-
Select Delivery to OSS, and then select Delivery to Current Account.
-
Create a new bucket: Configure the Bucket Name, Log File Prefix, server-side encryption, and whether to enable compliance retention.
-
Select an existing bucket: Select Bucket Name.
-
-
Select Delivery to MaxCompute, and then select Delivery to Current Account.
-
Set the MaxCompute Region and Project Quota.
-
-
-
-
Click Confirm.
After the trail is created, view events in the destination service console:
-
OSS: Click the bucket name to view events in the OSS console.
-
SLS: Click the Project or Logstore name to view events in the SLS console.
-
MaxCompute: Click the project name to view events in the MaxCompute console.
-
Scenario 2: Analyze and alert on sensitive operations
-
Log on to the ActionTrail console.
-
In the left navigation bar, click Trail.
-
In the top navigation bar, select the region where you want to create the trail.
-
On the Trail page, click Create Trail.
-
On the Create Trail page, configure the parameters for the trail.
-
In the Basic Information section, configure the following parameters.
Parameter
Description
Trail Name
Must be unique within your Alibaba Cloud account.
Trail Configuration
Set Write to Write.
NoteSensitive operations are typically Writes. Selecting only Writes reduces audit data volume and costs.
-
In the Event Delivery Settings section, select Log Service in the current account as the delivery destination.
-
New Log Service Project: Select a Logstore Region and enter a Project Name.
-
Existing Log Service Project: Select a Logstore Region and a Project Name.
-
-
-
Click Confirm.
Click the Project or Logstore name to view event analysis in the SLS console.
-
Configure alerts in the Log Service console.
Scenario 3: Analyze events with MaxCompute
-
Log on to the ActionTrail console.
-
In the left navigation bar, click > Trail.
-
In the top navigation bar, select the region where you want to create the trail.
-
On the Trail page, click Create Trail.
-
On the Create Trail page, configure the parameters for the trail.
-
In the Basic Information section, configure the trail parameters.
Parameter
Description
Trail Name
Must be unique within your Alibaba Cloud account.
Trail Configuration
Set All Events to All Events.
-
In the Event Delivery Settings section, select Log Service in the current account as the delivery destination.
-
New Log Service Project: Select a Logstore Region and enter a Project Name.
-
Existing Log Service Project: Select a Logstore Region and a Project Name.
-
-
-
Click Confirm.
Click the Project or Logstore name to view event analysis in the SLS console.
-
In the Log Service console, deliver the events to MaxCompute.
Create a MaxCompute delivery job (new version).
NoteYou can then analyze events in MaxCompute as needed.
Scenario 4: Cost-effectively analyze and permanently store events
When you select New Log Service Project, a Logstore whose name starts with actiontrail_<trail_name> is created to permanently store events. To reduce costs, set a shorter retention period in SLS (for example, 180 days) and periodically export data to MaxCompute or OSS for permanent storage.
-
Create a trail in the ActionTrail console and deliver events to Log Service (SLS).
To create a trail, follow Create a single-account trail.
-
Modify the log retention period in the Log Service console.
-
Log on to the Log Service console.
-
In the Projects section, click the name of the Project that contains the events.
-
Click the
icon next to the Logstore name, and then click the
icon. -
On the Logstore Attributes page, click Modify in the upper-right corner.
-
Change Data Retention Period to Specified Days, enter the retention period in days, and then click Save in the upper-right corner.
-
-
In the Log Service console, deliver the events to MaxCompute or OSS.