ActionTrail retains events for 90 days by default. To query events older than 90 days or store them long-term, create a trail to deliver events to Simple Log Service or Object Storage Service (OSS).
ActionTrail maintains a 90-day rolling window of events for your Alibaba Cloud account. Events outside this window are no longer queryable unless you have a trail configured.
Limitations of the default 90-day retention
Without a trail, the following limitations apply:
Events older than 90 days cannot be queried.
You cannot reconstruct who created or modified a resource before the retention window.
You cannot meet compliance requirements that mandate longer retention periods, such as Multi-Level Protection Scheme (MLPS) 2.0, which requires at least 180 days of event retention.
Extend event retention with a trail
To retain events beyond 90 days, create a trail to deliver events to a destination you control. By default, events are permanently stored after they are delivered to a Simple Log Service Logstore or an OSS bucket.
Supported destinations:
Simple Log Service Logstore: Query events using the Simple Log Service console. Configure retention duration in the Logstore settings.
OSS bucket: Archive events as log files for long-term storage and offline analysis.
To get started: