If you log on to the Alibaba Cloud console by using an Alibaba Cloud account, a logon event (ConsoleSignin) is generated. This topic describes the fields in sample event logs for logons by using an Alibaba Cloud account.

Example 1: Logon without MFA enabled

The following sample event log indicates that the Alibaba Cloud account 151266687691**** without multi-factor authentication (MFA) enabled is used to log on to the Alibaba Cloud console at 08:00:00 (UTC+8) on January 1, 2021.

{
  "requestId": "2546c4b7-6b56-403e-97d3-500d8d29339a",
  "eventType": "ConsoleSignin",
  "userIdentity": {
    "accountId": "151266687691****",
    "principalId": "151266687691****",
    "type": "root-account",
    "userName": "root"
  },
  "AcsRegion": "cn-hangzhou",
  "eventName": "ConsoleSignin",
  "eventSource": "http://account.aliyun.com/login/login_aliyun.htm",
  "serviceName": "AasCustomer",
  "eventTime": "2021-01-01T00:00:00Z",
  "userAgent": "Mozilla/5.0 (iPhone; CPU iPhone OS 15_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/19A5307g Ariver/1.1.0 AliApp(AP/10.2.28.6000) Nebula WK RVKType(1) AlipayDefined(nt:WIFI,ws:390|780|3.0) AlipayClient/10.2.28.6000 Language/zh-Hans Region/CN NebulaX/1.0.0",
  "eventId": "2546c4b7-6b56-403e-97d3-500d8d29****",
  "additionalEventData": {
    "loginAccount": "Alice",
    "isMFAChecked": "false"
  },
  "errorCode": "",
  "errorMessage": "",
  "eventVersion": "1",
  "sourceIpAddress": "192.168.XX.XX"
}

The sample event log contains the following key fields:

  • eventType: the type of the event. The value is ConsoleSignin, which indicates a console logon event.
  • userIdentity.accountId: the ID of the Alibaba Cloud account used by the requester.
  • userIdentity.type: the identity type of the requester. The value is root-account, which indicates an Alibaba Cloud account.
  • eventTime: the time when the event occurred in UTC. In this example, the value is 2021-01-01T00:00:00Z, which indicates 08:00:00 (UTC+8) on January 1, 2021.
  • additionalEventData.isMFAChecked: indicates whether MFA is enabled. A value of false indicates that MFA is not enabled.

Example 2: Logon with MFA enabled

The following sample event log indicates that the Alibaba Cloud account 151266687691**** with MFA enabled is used to log on to the Alibaba Cloud console at 08:00:00 (UTC+8) on January 1, 2021.

{
  "eventId": "2546c4b7-6b56-403e-97d3-500d8d29****",
  "eventVersion": 1,
  "eventSource": "http://account.aliyun.com/account_init/skip2Login.htm",
  "sourceIpAddress": "192.168.XX.XX",
  "userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36",
  "eventType": "ConsoleSignin",
  "userIdentity": {
    "accountId": "151266687691****",
    "principalId": "151266687691****",
    "type": "root-account",
    "userName": "root"
  },
  "serviceName": "AasCustomer",
  "additionalEventData": {
    "loginAccount": "Alice",
    "isMFAChecked": "true"
  },
  "extend": "2",
  "requestId": "2546c4b7-6b56-403e-97d3-500d8d29339a",
  "eventTime": "2021-01-01T00:00:00Z",
  "isGlobal": true,
  "acsRegion": "cn-hangzhou",
  "eventName": "ConsoleSignin"
}

The sample event log contains the following key fields:

  • eventType: the type of the event. The value is ConsoleSignin, which indicates a console logon event.
  • userIdentity.accountId: the ID of the Alibaba Cloud account used by the requester.
  • userIdentity.type: the identity type of the requester. The value is root-account, which indicates an Alibaba Cloud account.
  • additionalEventData.isMFAChecked: indicates whether MFA is enabled. A value of true indicates that MFA is enabled.
  • eventTime: the time when the event occurred in UTC. In this example, the value is 2021-01-01T00:00:00Z, which indicates 08:00:00 (UTC+8) on January 1, 2021.

Example 3: Failed logon

The following sample event log indicates that the Alibaba Cloud account 151266687691**** failed to log on to the Alibaba Cloud console at 08:00:00 (UTC+8) on January 1, 2021.

{
  "requestId": "2546c4b7-6b56-403e-97d3-500d8d29339a",
  "eventType": "ConsoleSignin",
  "userIdentity": {
    "accountId": "151266687691****",
    "principalId": "151266687691****",
    "type": "root-account",
    "userName": "root"
  },
  "AcsRegion": "cn-hangzhou",
  "eventName": "ConsoleSignin",
  "eventSource": "http://account.aliyun.com/login/login_aliyun.htm",
  "serviceName": "AasCustomer",
  "eventTime": "2021-01-01T00:00:00Z",
  "userAgent": "Mozilla/5.0 (iPhone; CPU iPhone OS 15_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/19A5307g Ariver/1.1.0 AliApp(AP/10.2.28.6000) Nebula WK RVKType(1) AlipayDefined(nt:WIFI,ws:390|780|3.0) AlipayClient/10.2.28.6000 Language/zh-Hans Region/CN NebulaX/1.0.0",
  "eventId": "2546c4b7-6b56-403e-97d3-500d8d29****",
  "additionalEventData": {
    "callbackUrl": "https://actiontrail.console.aliyun.com/cn-hangzhou/event-list?accounttraceid=******",
    "mfaChecked": "false"
  },
  "errorCode": "Authentication.Failed",
  "errorMessage": "Failed authentication.",
  "eventVersion": "1",
  "sourceIpAddress": "192.168.XX.XX"
}

The sample event log contains the following key fields:

  • eventType: the type of the event. The value is ConsoleSignin, which indicates a console logon event.
  • userIdentity.accountId: the ID of the Alibaba Cloud account used by the requester.
  • userIdentity.type: the identity type of the requester. The value is root-account, which indicates an Alibaba Cloud account.
  • eventTime: the time when the event occurred in UTC. In this example, the value is 2021-01-01T00:00:00Z, which indicates 08:00:00 (UTC+8) on January 1, 2021.
  • errorCode: the error code. A value of Authentication.Failed indicates a failed logon.