Audit alerts
Audit alerts record detailed information about database activity. Use audit alerts to track potential malicious activity or unauthorized access and investigate security incidents. Audit alerts also help you meet compliance requirements. This topic describes how to view audit alerts.
Prerequisites
Security audit is enabled. For more information, see Enable security audit.
Audit alerts for a single instance
Log on to the ApsaraDB Security Center console.
Find the target instance and click the instance ID to open the instance details page.
In the left-side navigation pane, click Security Audit.
On the Security Audit page, click .
View the audit alerts for the database instance.
Analysis Mode
After you select a time range, DAS displays database activity from newest to oldest.
In the Actions column, click Details for the desired record to view more information.
List Mode
In the Actions column, click Details for the desired record to view more information.
Audit alerts for all instances
If you have enabled security audit for multiple database instances, you can view their audit alerts on a single page.
Log on to the ApsaraDB Security Center console.
Click .
View the audit alerts for your database instances.
Analysis Mode
After you select a time range, DAS displays database activity from newest to oldest.
In the Actions column, click Details for the desired record to view more information.
List Mode
In the Actions column, click Details for the desired record to view more information.
Export logs
Log on to the ApsaraDB Security Center console.
Find the target instance and click the instance ID to open the instance details page.
In the left-side navigation pane, click Security Audit.
On the Security Audit page, choose Audit alerts > Alert Logs.
Select a time range and other filters, and then click Search.
Click Export.
This exports all log records on the current page.
Related documents
By default, Database Security Center enables all built-in database audit rules. You can disable any rules that you do not need. For more information, see Configure alert rules.