Enable audit logs

更新时间:
复制 MD 格式

ApsaraDB for MongoDB provides an audit log feature powered by Log Service. This feature allows you to query, analyze, and export logs, giving you real-time insight into the security and performance of your instance.

Background

Alibaba Cloud Log Service (SLS) is a one-stop service for log data processing, built on Alibaba Group's extensive big data experience. It enables you to collect, consume, route, query, and analyze log data without writing code, which improves O&M and operational efficiency. ApsaraDB for MongoDB integrates key features of Log Service to provide a stable, user-friendly, flexible, and efficient audit log service.

Prerequisites

  • The instance is a general-purpose instance with local disks or a dedicated instance with local disks.

  • If you use a RAM user to enable audit logs, you must grant the RAM user the AliyunLogFullAccess permission. For more information, see Grant permissions to a RAM user.

Limitations

Impacts

  • Enabling the free trial edition of the audit log feature has a minor impact on the performance of your ApsaraDB for MongoDB instance.

  • After you enable the free trial edition, Log Service records all operations performed on your ApsaraDB for MongoDB instance. You can use these logs for troubleshooting.

Procedure

  1. Go to the Replica Set Instances or Sharded Cluster Instances page. In the top navigation bar, select a resource group and a region. Then, click the ID of the target instance.

  2. In the left-side navigation pane of the instance details page, choose Data Security > Audit Logs.

  3. On the Latest Audit Logs page, for Version, select Free Trial, and then click Activate.

  4. In the Enable Audit Logs dialog box, review the information and click Confirm.