The User tab in the IDaaS EIAM log module records every action users take in the system — logins, authenticator registrations, organization changes, and more. Use it to monitor user activity, investigate anomalies, and run security audits.
Each log entry captures the time, the actor, the event type, the target object, and the outcome. You can filter by any combination of these dimensions and export results to Simple Log Service (SLS) for long-term retention or downstream analysis.
Prerequisites
Before you begin, ensure that you have:
An IDaaS instance with EIAM enabled
Admin access to the IDaaS console
Query user behavior logs
Log on to the IDaaS console.IDaaS console
In the left-side navigation pane, click EIAM.
Select the corresponding IDaaS instance, then click Manage in the operation column.
Go to Log > User.
Set your filters. All filters are optional — combine them to narrow results.
Time range
Select a preset period or enter a custom date range:
Option Period Last week 7 days Last month 30 days Last three months 90 days Last six months 180 days Custom Any date range you specify Advanced search
Filter Description Example values Operator type The category of actor who performed the action IDaaS account, IDaaS application, Resource Access Management (RAM) user, RAM role Event type The specific action that was performed Account joining organization, registering authenticator Object type The resource that was acted on Account, organization, user group, identity provider, application Event result Whether the action succeeded Success/skipped, failed Click Search to run the query.
To clear all filters, click Reset.
To collapse the filter panel after searching, select the Search and collapse checkbox.
Review results in the table at the bottom of the page.
Column Description Time When the event occurred Operator The user ID or name of the actor Event type The action performed, such as basic authentication or user performing CAPTCHA Operation object The resource that was acted on, such as User Portal or Password Event result Whether the action succeeded or failed To view the full details of an event, click any row in the table.
What's next
To retain logs beyond the console or feed them into a SIEM or analytics pipeline, export them to SLS. See Export IDaaS logs to Alibaba Cloud Simple Log Service (SLS).