This topic describes how to create a trail for data events in the ActionTrail console.
Procedure
-
Log in to the ActionTrail console.
In the left-side navigation pane, click Trails.
-
In the top navigation bar, select the region where you want to create a single-account trail.
The selected region becomes the home region of the single-account trail.
On the Trails page, click Create Trail.
On the Create Trail page, select Data Event for the Trail Event Type parameter.
In the Data Event Delivery Settings section, select the regions where you want to track data events. ActionTrail then processes and delivers these events to Log Service (SLS) in their respective regions.
Configure the Delivery Rules of Data Events:
You can track all supported Alibaba Cloud services or configure custom data event selectors. ActionTrail delivers a data event to your specified SLS project if the event matches the specified read/write type, event name, and resource ARN. You can configure a maximum of 20 custom data event selectors.
|
Parameter |
Description |
|
Cloud service name |
Select the Alibaba Cloud service to track. For a list of supported services, see Supported Alibaba Cloud services for data events. |
|
Read/write type |
Select the read/write type of the data events to track:
|
|
Event name |
Select the name of the data event to record. To track all events, select "All events". |
|
Resource ARN |
Enter the Alibaba Cloud Resource Name (ARN) of the resource to track. You can set multiple conditions that use the 'equals' or 'does not equal' operators for specific resource ARNs. These conditions are combined with a logical OR. A data event is delivered only if its associated resource meets at least one of the specified filter conditions. |
Results
In each region where you create a data event trail, ActionTrail creates a log project named 'actiontrail-log-<Account ID>-<Region ID>' and a Logstore named 'actiontrail_<Trail Name>' within that project. The trail details page displays the log projects created in each region and their details.
After you create a data event trail, events are delivered to a dedicated SLS Logstore. You can then query and analyze the data events in SLS.