Query Tablestore operation events in the ActionTrail console to audit operations or troubleshoot issues.
Notes
By default, ActionTrail records only management events for Tablestore and retains them for 90 days. To audit data events or query events older than 90 days, you must create a trail to deliver the management events and data events to Simple Log Service, Object Storage Service, or MaxCompute. For more information, see Advanced event query.
Procedure
The Event Query page in the ActionTrail console displays Tablestore operation events from the last 90 days.
-
Log on to the ActionTrail console.
-
In the left-side navigation pane, choose Events > Event Query.
-
In the top navigation bar, select the target region.
-
On the Event Query page, set Service Name to Tablestore(OTS) and select a time range as needed.
NoteYou can also filter events by criteria such as Event Name, Operator, Read/Write Type, Resource Type, Resource Name, AccessKey ID, Source IP Address, Event ID, Event Type, and Sensitive Action. If you cannot find data events in the list, you must first create a trail to enable data event collection. For more information, see the Notes section.
The page then lists the matching Tablestore events.
-
View event details.
-
In the Actions column for an event, click View Details.
-
The View Details panel displays detailed event information and the event list.
The Basic Information section contains the Event Name, Cloud Service Name, Operator, Source IP Address, Result, and Sensitive Action fields. The Event List section displays a table with columns for Event Time, Event ID, Associated Resource, Region, and Actions. In the Actions column, you can click Event Record or Open Details.
-
In the Actions column for an event, click Event Record to view its raw content.
-