Integrate with ActionTrail (Security)

更新时间:
复制 MD 格式

Centralize security event monitoring by integrating ActionTrail identity authentication logs into Cloud Monitor.

Prerequisites

Billing

Procedure

  1. Log on to the Cloud Monitor console. Select the target workspace. In the left-side navigation pane, click Integration Center, and then click ActionTrail (Security).

  2. Configure the integration settings as needed, and then click OK.

    Parameter

    Description

    Integration Name

    Optional. A name for the integration.

    Trail Project

    A trail is automatically created, and logs are delivered to this SLS project. The default project name is aliyun-product-data-{{.Release.UserID}}-{{ .Workspace.Region }}. The Logstore name is fixed to actiontrail_{{integration_policy_id}}.

  3. After the integration is complete, view the integrated entities and observable data in Entity Explorer.

Storage policy

After integration, Cloud Monitor automatically creates an SLS Logstore and a Prometheus instance to store observable data.

Type

Default Storage Location

Notes

metric

Prometheus instance: RegionShare:{{workspaceName}}:{{regionId}}

None

Integrated logs

SLS Project: aliyun-product-data-{{userId}}-{{regionId}}

SLS Logstore: actiontrail_{{integration_policy_id}}

None

Delete or modify an integration policy

To modify or delete your ActionTrail integration, go to Integration Center > Integration Management, find the corresponding integration policy, and then click Edit or Delete.