Use ActionTrail system templates to quickly query events related to your Alibaba Cloud account or AccessKey pairs. Available templates cover Alibaba Cloud account console logons, Alibaba Cloud account AccessKey pair access, RAM user logons without MFA, and failed AccessKey pair access. The following procedure uses the console logon events template as an example.
Prerequisites
A trail is created and events are delivered to Simple Log Service: Create a single-account trail | Create a multi-account trail.
Procedure
-
Log on to the ActionTrail console.
-
In the left-side navigation pane, choose .
-
In the Query Range section, select your trail from the Trails drop-down list.
-
In the Query Range section, click the Template Library tab and choose .
-
On the Events of Console Logons by Using Cloud Account tab, specify a time range and then click Run.
Note-
By default, ActionTrail queries events from the past seven days.
-
Click Event Alerting on the right to configure an alert for the current query. Create a custom alert rule.
-
Modify the default SQL statement in the system template, then click Save to save it as a custom template.
-
-
View the query results.
-
Raw log
On the Raw Logs tab, find the target event and click View Details in the Actions column to view basic information and JSON details.
-
Histogram
The Query Histogram tab displays a histogram of the events.
-
References
To configure query conditions or write custom SQL statements, see Perform custom event queries.