All Products
Search
Document Center

ActionTrail:Query Insights events in the ActionTrail console

Last Updated:Jun 16, 2026

The Insights feature uses mathematical models to analyze management events in your Alibaba Cloud account and identify unusual activities. After Insights is enabled, ActionTrail detects anomalies in API call rates, API error rates, IP addresses, and AccessKey pair call rates, and generates Insights events. You can query these events in the ActionTrail console to monitor management risks and take timely remedial action. This example uses a single-account trail and queries Insights events for unusual API call rates.

Prerequisites

A single-account trail that meets the following conditions exists:

  • The trail delivers events from all regions.

  • The trail delivers all types of events.

For more information, see Create a single-account trail.

Note

If no unusual activities are detected in your Alibaba Cloud account, no Insights events are generated.

Step 1: Enable the Insights feature

  1. Log on to the ActionTrail console.

  2. In the left-side navigation pane, click Insights.

  3. On the Insights page, click Enable Insights.

    Note

    After Insights is enabled, ActionTrail generates the first Insights event after at least 24 hours.

Step 2: Query Insights events

  1. In the left-side navigation pane, click Insights.

  2. In the top navigation bar, select the region of the Insights events that you want to query.

  3. On the Insights page, set Event Type to ApiCallRateInsight and click the 查询按钮 icon.

    Note

    You can also specify a single search condition such as IP Address or Event Type to query Insights events.

  4. In the Actions column of the target Insights event, click View Event Details.

  5. In the Insights Events section, click the target Insights event record.

    The Insights Event tab also shows the Insights Trend Chart, which displays how the anomaly trend changes over time.

    • The Insights Events tab displays the Basic Information and Multi-dimensional Aggregation Analysis of the selected event record.

    • The Related Events tab lists all related management events and their details.

    • The Insights Event Records tab displays the JSON-formatted content of the event record.

      Note

      For more information about the fields in an Insights event, see Insights event structure.

References

  • You can use the advanced event query feature to query Insights events. For more information, see Custom event queries.

  • You can query and analyze Insights events in the Simple Log Service or Object Storage Service (OSS) console. For more information, see Query events in the Simple Log Service or OSS console.

  • To obtain details of Insights events delivered to Simple Log Service and perform in-depth analysis, you can use query statements. For more information, see Analyze events in SLS.