PAM logs

Updated at:

This topic describes the fields in O&M audit logs and operation audit logs from Privileged Access Management (PAM).

O&M audit logs

Field name

Description

user_id

The user ID.

instance_id

The instance ID.

operator_id

The O&M operator ID.

user_type

The user type. Valid values include the following:

  • RAM_ROOT: Alibaba Cloud account

  • RAM_SUB_USER: RAM user

  • BUILTIN: Local PAM account

system_account

The system account name.

asset_ip

The IP address of the asset.

asset_name

The asset name.

asset_port

The asset port.

asset_region_id

The region where the asset is located.

asset_id

The asset ID.

asset_type

The asset type. Valid values include the following:

  • Ecs: Elastic Compute Service (ECS)

  • Ack: Container Service for Kubernetes (ACK)

content

The content of the instruction.

credential_name

The credential name.

event_time

The time when the event occurred.

intercepted

Indicates whether the session was intercepted.

protocol_type

The protocol type. Valid values include the following:

  • ssh: Secure Shell (SSH) protocol

  • rdp: Remote Desktop Protocol (RDP)

  • k8s: kubectl exec protocol

region_id

The region where the session occurred.

session_id

The unique ID of the session.

source_ip

The source IP address.

event_type

The event type. Valid values include the following:

  • session: session

  • cmd: command

event_sub_type

Event subtype

  • close: The session is closed.

  • open: The session starts.

  • command: An instruction is executed.

  • update_asset_fingerprint: The asset fingerprint is updated.

video_size

The size of the video recording.

Operation audit logs

Field name

Description

user_id

The user ID.

instance_id

The instance ID.

event_sub_type

The event subtype. Valid values include the following:

  • FILE_Upload: A file is uploaded.

  • FILE_Download: A file is downloaded.

event_type

The event type. The value is FILE, which indicates a file-related operation.

event_detail

The event details.

event_content

The event content.

event_id

Event UUID

user_name

The username of the operator.

user_type

The type of the operator. Valid values include the following:

  • RAM_ROOT: Alibaba Cloud account

  • RAM_SUB_USER: RAM user

  • BUILTIN: Local PAM account

operator_id

The operator ID.

start_time

The time when the event started.

end_time

The time when the event ended.