Bastionhost

Updated at:

This topic describes the fields in the operation log entries that are generated by Bastionhost.

SLS log field

Description

__topic__

The log topic. The value is fixed to `bastionhost`.

owner_id

The Alibaba Cloud account ID.

region

The region where the Bastionhost instance resides.

content

The content of an operation, such as a character command or a file transfer.

event_type

The event type. For more information, see event_type details.

instance_id

The ID of the Bastionhost instance.

resource_address

The IP address of the O&M asset.

resource_name

The name of the O&M asset.

result

The result of an operation, such as a character command or a file transfer.

session_id

The session ID. This is the unique identifier for a session.

user_client_ip

The source IP address of the user. This is the IP address used to access Bastionhost.

threat_user_client_ip

Threat intelligence for the user's source IP address. This is not part of the raw Bastionhost log.

Note

Log Audit Service can perform threat intelligence detection on the logs of cloud products that are connected to it. This helps to effectively identify potential threats when you use cloud products. For more information, see Generate threat intelligence.

user_id

The Bastionhost user ID. This is the unique identifier for a user.

user_name

The name of the Bastionhost user.