- What's New
- Function Overview
- Service Overview
- Getting Started
- User Guide
- Best Practices
- API Reference
- SDK Reference
-
FAQs
- Must I Use an IAM User (Sub Account) to Configure Transfer on CTS and Perform Operations on an OBS Bucket?
- How Will CTS Be Affected If My Account Is in Arrears?
- What Are the Recommended Users of CTS?
- What Will Happen If I Have Enabled Trace Transfer But Have Not Configured an Appropriate Policy for an OBS Bucket?
- Does CTS Support Integrity Verification of Trace Files?
- Why Are There Some Null Fields on the View Trace Page?
- Why Is an Operation Recorded Twice in the Trace List?
- What Services Are Supported by Key Event Notifications?
- How Can I Store Trace Files for a Long Time?
- Why Are user and source_ip Null for Some Traces with trace_type as SystemAction?
- How Can I Find Out Who Created a Specific ECS?
- How Can I Find Out the Login IP Address of an IAM User?
- Why Are Two deleteMetadata Traces Generated When I Buy an ECS in Pay-per-Use or Yearly/Monthly?
- What Can I Do If I Cannot Query Traces?
- Can I Disable CTS?
- How Do I Configure the Storage Duration of CTS Audit Logs to 180 Days?
- What Should I Do If I Cannot Enable CTS as an IAM User?
- How Do I Enable Alarm Notifications for EVS?
- Videos
Enabling CTS
Scenarios
You need to enable Cloud Trace Service (CTS) before using it to record operations on resources. After being enabled, CTS automatically creates a management tracker named system and records all operations of your tenant account in the tracker. CTS displays traces generated in the last seven days. To store traces for a long time, you can transfer them to Object Storage Service (OBS). Ensure that you have enabled OBS and have full permissions for the OBS bucket you are going to use.
This section describes how to enable CTS.
Associated Services
- OBS: used to store trace files.
NOTE:
You must select a standard OBS bucket because CTS needs to frequently access the OBS bucket that stores traces.
- Data Encryption Workshop (DEW): Provides keys that can be used to encrypt trace files.
- Simple Message Notification (SMN): Sends email or SMS message notifications to users when key operations are performed.
Procedure
- Log in to the management console.
- If you have logged in as an account administrator, go to 3 directly. If you have logged in as an IAM user, first contact your administrator (account owner, a user in the admin user group, or a user who has been granted the Security Administrator permissions) to obtain the following permissions:
- Security Administrator
- CTS FullAccess
For details, see Assigning Permissions to an IAM User.
- Click
in the upper left corner and choose Management & Deployment > Cloud Trace Service. The CTS authorization page is displayed.
Figure 1 Enabling CTS - Click Enable and Authorize.
NOTE:
After you enable CTS, two trackers are automatically created to record management traces, which are operations (such as creation, login, and deletion) performed on all cloud resources.
- In the current region, a tracker is created to record management traces of all project-level services deployed in this region.
- In the EU-Dublin region, a tracker is created to record management traces of all global services, such as IAM.
When using CTS, you only need the required permissions for relevant operations, but do not need the Security Administrator permissions.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.