Enable the Inner-ActionTrail feature to collect platform operation logs through the Log Service console.
Prerequisites
-
You have submitted a ticket or contacted your sales manager to obtain Inner-ActionTrail permissions.
-
ActionTrail is authorized to use the AliyunActionTrailDefaultRole role to deliver logs to Log Service.
Click Cloud Resource Access Authorization to complete authorization. This is required only during initial setup and must be performed with an Alibaba Cloud account.
WarningDo not revoke the authorization or delete the AliyunActionTrailDefaultRole role. Otherwise, logs cannot be delivered to Log Service.
-
You have created a project and a Logstore. For more information, see Create a project and a Logstore.
Procedure
If you use a RAM user to enable the log analysis feature, you must first grant permissions to the RAM user. For more information, see Authorize a RAM user.
Log on to the Simple Log Service console.
-
In the Import Data section, click Inner-ActionTrail Logs.
Alternatively, log on to the ActionTrail console and navigate to to collect platform operation logs.
Important-
If you enable the Inner-ActionTrail feature from the ActionTrail console, a dedicated Logstore named
innertrail_<Trail Name>is automatically created. -
Enabling Inner-ActionTrail from the Log Service console does not synchronize settings to the ActionTrail console. If you later create a trail on the ActionTrail console, the ActionTrail configuration overwrites the Log Service configuration.
-
If you cannot find Import Data in the Inner-ActionTrail Logs section of the Log Service console, or if you cannot find the page on the ActionTrail console, submit a ticket or contact your sales manager to request permission to use the Inner-ActionTrail feature.
-
-
Select the destination project and Logstore, and then click Next.
-
On the Data Source Configuration tab, click Next.
The page shows that ActionTrail Authorization is complete and Platform Operation Log (Inner-ActionTrail) is not yet enabled. After you enable this feature, the default data retention period for the Logstore is 180 days.
Important-
All Inner-ActionTrail logs can be delivered to only one Logstore.
-
You can disable the Inner-ActionTrail feature on the Data Source Configuration tab.
-
If you enabled the Inner-ActionTrail feature in the ActionTrail console, disable log delivery by deleting the trail on the page.
-
After disabling log delivery, new Inner-ActionTrail logs are no longer delivered to the Logstore. Existing logs are automatically deleted after their retention period expires.
-
-
On the Query and Analysis Configurations tab, click Next.
By default, Log Service enables and configures indexes for the Logstore that stores Inner-ActionTrail logs.
Next steps
After Inner-ActionTrail logs are collected, you can query, analyze, download, deliver, and transform logs, and create alerts. For more information, see Common operations on logs of Alibaba Cloud services.