A trail delivers only events generated after it is created. To query and analyze events from before the trail was created, you can create a data backfill task to deliver events generated within the last 90 days.
Prerequisites
-
You have the permissions to use the backfill feature. To obtain the permissions, submit a ticket or contact your sales manager to add your account to the whitelist.
-
A trail is created in the current region. For more information, see Create a single-account trail.
Limits
-
Events can be delivered only to Simple Log Service.
-
Only one data backfill task can be run at a time within an Alibaba Cloud account.
-
Data backfill supports only management events, not data events.
Procedure
-
Log on to the ActionTrail console.
-
In the left-side navigation pane, click Backfill.
-
In the top navigation bar, select the region where you want to create a data backfill task.
NoteThis region must be the same as the region where the trail resides.
-
On the Backfill page, click Create Task.
-
On the Create Task page, select the trail for which you want to create a data backfill task.
NoteAfter you select the trail, the following information is automatically populated: the event delivery region, the Simple Log Service project region and name, and the Logstore information.
-
Click Confirm.
After the task is created, you can view its details on the Backfill page, including the associated trail, backfill time range, delivery status, and creation and completion times.
Note-
A data backfill task delivers only events whose type and region match those specified when the trail was created. For example, if Trail A collects write events in the China (Hangzhou) region, the associated backfill task delivers the write events generated in the China (Hangzhou) region within the last 90 days to the specified destination.
-
A data backfill task delivers only the events generated from 90 days before the current time to 5 minutes after the associated trail takes effect. For example, if you create Trail A 40 days before you create the backfill task, the task delivers only the events generated in the 50 days before Trail A was created.
-
What to do next
After the data backfill task is created, events are stored in JSON format in the Simple Log Service Logstore configured for your trail. You can then query and analyze the events in the Logstore. For more information, see Query and analyze logs.
References
-
You can query and download events of the last 90 days in the ActionTrail console. For more information, see Query events in the ActionTrail console.
-
You can download event query or analysis results to your on-premises computer from the Simple Log Service console. For more information, see Download logs.