Centralize security event monitoring by integrating ActionTrail identity authentication logs into Cloud Monitor.
Prerequisites
-
You have activated SLS.
-
You have activated Managed Service for Prometheus and Cloud Monitor.
-
If you use a RAM user for the integration, you must grant the
AliyunCloudMonitorFullAccesssystem policy to the RAM user.
Billing
-
Integrating metrics incurs fees for real-time data export from Cloud Monitor and fees for Managed Service for Prometheus.
-
Log integration is billed based on SLS pricing.
Procedure
-
Log on to the Cloud Monitor console. Select the target workspace. In the left-side navigation pane, click Integration Center, and then click ActionTrail (Security).
-
Configure the integration settings as needed, and then click OK.
Parameter
Description
Integration Name
Optional. A name for the integration.
Trail Project
A trail is automatically created, and logs are delivered to this SLS project. The default project name is aliyun-product-data-{{.Release.UserID}}-{{ .Workspace.Region }}. The Logstore name is fixed to actiontrail_{{integration_policy_id}}.
-
After the integration is complete, view the integrated entities and observable data in Entity Explorer.
Storage policy
After integration, Cloud Monitor automatically creates an SLS Logstore and a Prometheus instance to store observable data.
|
Type |
Default Storage Location |
Notes |
|
metric |
Prometheus instance: RegionShare:{{workspaceName}}:{{regionId}} |
None |
|
Integrated logs |
SLS Project: aliyun-product-data-{{userId}}-{{regionId}} SLS Logstore: actiontrail_{{integration_policy_id}} |
None |
Delete or modify an integration policy
To modify or delete your ActionTrail integration, go to Integration Center > Integration Management, find the corresponding integration policy, and then click Edit or Delete.