All Products
Search
Document Center

Identity as a Service:User behavior

Last Updated:Mar 31, 2026

The User tab in the IDaaS EIAM log module records every action users take in the system — logins, authenticator registrations, organization changes, and more. Use it to monitor user activity, investigate anomalies, and run security audits.

Each log entry captures the time, the actor, the event type, the target object, and the outcome. You can filter by any combination of these dimensions and export results to Simple Log Service (SLS) for long-term retention or downstream analysis.

Prerequisites

Before you begin, ensure that you have:

  • An IDaaS instance with EIAM enabled

  • Admin access to the IDaaS console

Query user behavior logs

  1. Log on to the IDaaS console.IDaaS console

  2. In the left-side navigation pane, click EIAM.

  3. Select the corresponding IDaaS instance, then click Manage in the operation column.

  4. Go to Log > User.

  5. Set your filters. All filters are optional — combine them to narrow results.

    Time range

    Select a preset period or enter a custom date range:

    OptionPeriod
    Last week7 days
    Last month30 days
    Last three months90 days
    Last six months180 days
    CustomAny date range you specify

    Advanced search

    FilterDescriptionExample values
    Operator typeThe category of actor who performed the actionIDaaS account, IDaaS application, Resource Access Management (RAM) user, RAM role
    Event typeThe specific action that was performedAccount joining organization, registering authenticator
    Object typeThe resource that was acted onAccount, organization, user group, identity provider, application
    Event resultWhether the action succeededSuccess/skipped, failed
  6. Click Search to run the query.

    • To clear all filters, click Reset.

    • To collapse the filter panel after searching, select the Search and collapse checkbox.

  7. Review results in the table at the bottom of the page.

    ColumnDescription
    TimeWhen the event occurred
    OperatorThe user ID or name of the actor
    Event typeThe action performed, such as basic authentication or user performing CAPTCHA
    Operation objectThe resource that was acted on, such as User Portal or Password
    Event resultWhether the action succeeded or failed
  8. To view the full details of an event, click any row in the table.

What's next

To retain logs beyond the console or feed them into a SIEM or analytics pipeline, export them to SLS. See Export IDaaS logs to Alibaba Cloud Simple Log Service (SLS).