All Products
Search
Document Center

ActionTrail:Query events by using ActionTrail

Last Updated:May 05, 2026

ActionTrail audits team member operations to help ensure the proper use of cloud services. For example, you can use ActionTrail to identify which RAM user performed an accidental operation and when. This topic uses a NAT gateway event as an example to describe how to query event details.

Background

A team manager uses an Alibaba Cloud account to create multiple RAM users for team members and grants them administrator permissions.

When a RAM user inspects a NAT gateway, they discover an extra elastic IP address associated with it. Because all team members have administrator permissions, any of them could have performed this action. In this scenario, you can use ActionTrail to query events and quickly identify who performed the operation.

Note

You can click an elastic IP address to view its details, such as the instance ID.

Procedure

  1. Log on to the ActionTrail console.

  2. In the left-side navigation pane, choose Events > Event Query.

  3. In the top navigation bar, select the target region.

  4. From the drop-down list, select Resource Name.

  5. Enter the instance ID of the elastic IP address, and then click the search icon 1.

  6. In the Actions column of the target event, click View Event Details to view the event details and record code.

    Note

    The event details show that RAM user B associated the elastic IP address with the NAT gateway at 16:24:56 on November 2, 2020.

References

For more information about how to query events, see Query events in the ActionTrail console.