Use ActionTrail system templates to retrieve and view log information about network and data security events.
Prerequisites
Make sure that you have created a trail and delivered events to Simple Log Service (SLS). For more information, see Create a single-account trail and Create a multi-account trail.
Background information
Network and data security best practices enable continuous, dynamic monitoring of your Alibaba Cloud resources, providing real-time visibility into their security and compliance status and reducing network security risks.
To help you detect high-risk actions, ActionTrail provides query templates based on network and data security best practices. Use the advanced event query feature to monitor and audit high-risk access events, including trail changes, audit trail stops, RAM role changes, and the disabling of Cloud Firewall.
Procedure
-
Log on to the ActionTrail console.
-
In the left-side navigation pane, choose .
-
In the Query Range section, select a trail from the Trail drop-down list.
-
In the Query Range section, on the Template Library tab, choose .
-
On the Trail Change Events tab, set a time range, and then click Run.
Note-
By default, ActionTrail queries events from the past seven days.
-
Click Event Alerting on the right to configure an alert for the current query. Create a custom alert rule.
-
Modify the default SQL statement in the system template, then click Save to save it as a custom template.
-
-
View the query results.
-
Raw Log
On the Raw Logs tab, find the target event and click View Event Details in the Actions column to view its basic information and event record.
NoteIn this example, the View Event Details panel shows that a Resource Access Management (RAM) user enabled the trail at 11:06:40 on January 10, 2024 in the China (Zhangjiakou) region.
The event details dialog box also includes an Associated Resources section, which lists the related ActionTrail trail resource and provides a link to its configuration timeline. The Event Record section displays the complete event data in JSON format.
-
Query Histogram
On the Query Histogram tab, view the histogram of events.
-
References
You can also query event details by setting filter conditions or specifying SQL statements. For more information, see Perform custom event queries.