All Products
Search
Document Center

ActionTrail:Query Alibaba Cloud account or AccessKey pair events

Last Updated:Jul 17, 2026

Use ActionTrail system templates to quickly query events related to your Alibaba Cloud account or AccessKey pairs. Available templates cover Alibaba Cloud account console logons, Alibaba Cloud account AccessKey pair access, RAM user logons without MFA, and failed AccessKey pair access. The following procedure uses the console logon events template as an example.

Prerequisites

A trail is created and events are delivered to Simple Log Service: Create a single-account trail | Create a multi-account trail.

Procedure

  1. Log on to the ActionTrail console.

  2. In the left-side navigation pane, choose Events > Advanced Event Query.

  3. In the Query Range section, select your trail from the Trails drop-down list.

  4. In the Query Range section, click the Template Library tab and choose System Template > Account-related or AccessKey pair-related Events > Events of Console Logons by Using Cloud Account.

  5. On the Events of Console Logons by Using Cloud Account tab, specify a time range and then click Run.

    Note
    • By default, ActionTrail queries events from the past seven days.

    • Click Event Alerting on the right to configure an alert for the current query. Create a custom alert rule.

    • Modify the default SQL statement in the system template, then click Save to save it as a custom template.

  6. View the query results.

    • Raw log

      On the Raw Logs tab, find the target event and click View Details in the Actions column to view basic information and JSON details.

    • Histogram

      The Query Histogram tab displays a histogram of the events.

References

To configure query conditions or write custom SQL statements, see Perform custom event queries.