ActionTrail records events from the last 90 days by default. To query older events, create a trail to deliver events to Simple Log Service or Object Storage Service (OSS), and then query the delivered events in the Simple Log Service or OSS console.
Prerequisites
A trail is created, and events are delivered to Simple Log Service or OSS. For more information, see Create a single-account trail and Create a multi-account trail.
Procedure
-
Log on to the ActionTrail console.
-
In the left-side navigation pane, click Trails.
-
On the Trails page, find the target trail, hover over the Storage Service column, and then click the name of the SLS Logstore or OSS bucket.
-
Query events in the Simple Log Service console: Click the name of the Logstore to query or analyze the delivered events in the Simple Log Service console.
-
OSS: Click the name of the OSS bucket. Click , select a storage path, download the events to your local computer, and then view and analyze them. For more information about storage paths, see OSS storage path.
NoteTo query and analyze events delivered to an OSS bucket, import the events from OSS to Simple Log Service. For more information, see Import data from OSS to Simple Log Service and Query and analyze logs.
-