Updated on 2026-08-25 GMT+08:00

Querying the Policy for SQL Audit Logs

Function

This API is used to query the policy for SQL audit logs.

Authorization Information

Each account has all the permissions required to call all APIs, but IAM users must be assigned the required permissions.
  • If you are using role/policy-based authorization, see Permissions and Supported Actions for details on the required permissions.
  • If you are using identity policy-based authorization, the following identity policy-based permissions are required.

Action

Access Level

Resource Type (*: required)

Condition Key

Alias

Dependencies

rds:auditlog:list

read

instance

g:EnterpriseProjectId

g:ResourceTag/<tag-key>

-

-

URI

  • URI format

    GET /v3/{project_id}/instances/{instance_id}/auditlog-policy

  • Parameter description
    Table 1 Parameters

    Parameter

    Mandatory

    Description

    project_id

    Yes

    Definition

    Project ID of a tenant in a region.

    To obtain the value, see Obtaining a Project ID.

    Constraints

    N/A

    Range

    N/A

    Default Value

    N/A

    instance_id

    Yes

    Definition

    Instance ID.

    You can obtain the value of this parameter from id in Table 4 by calling the API for querying DB instances.

    Constraints

    N/A

    Range

    N/A

    Default Value

    N/A

Request

  • Request parameters

    None

  • URI example

    GET https://{endpoint}/v3/0483b6b16e954cb88930a360d2c4e663/instances/cee5265e1e5845649e354841234567dfin01/auditlog-policy

Response

  • Normal response
    Table 2 Parameters

    Parameter

    Type

    Description

    keep_days

    Integer

    Definition

    Number of days for storing audit logs.

    Range

    • 0: The audit log policy is disabled.
    • 1 to 3660: The audit log policy is enabled and the retention days are specified by this value.

    audit_types

    Array of strings

    Definition

    Actual operation types recorded in audit logs.

    Range

    • If this parameter is left blank, all operation types will be recorded.
    • The following operation types can be recorded:
      • Supported DCL operations: CREATE_USER, DROP_USER, RENAME_USER, GRANT, REVOKE, ALTER_USER, and ALTER_USER_DEFAULT_ROLE
      • Supported DDL operations: CREATE, ALTER, DROP, RENAME, TRUNCATE, REPAIR, and OPTIMIZE
      • Supported DML operations: INSERT, DELETE, UPDATE, REPLACE, and SELECT
      • Supported other operations: BEGIN/COMMIT/ROLLBACK, PREPARED_STATEMENT, CALL_PROCEDURE, KILL, SET_OPTION, CHANGE_DB, UNINSTALL_PLUGIN, UNINSTALL_PLUGIN, INSTALL_PLUGIN, SHUTDOWN, SLAVE_START, SLAVE_STOP, LOCK_TABLES, UNLOCK_TABLES, FLUSH, and XA

    all_audit_log_action

    String

    Definition

    All operation types that can be recorded in audit logs.

    Range

    {\"DCL\":\"CREATE_USER,DROP_USER,RENAME_USER,GRANT,REVOKE,ALTER_USER,ALTER_USER_DEFAULT_ROLE\",\"DDL\":\"CREATE,ALTER,DROP,RENAME,TRUNCATE,REPAIR,OPTIMIZE\",\"DML\":\"INSERT,DELETE,UPDATE,REPLACE,SELECT\",\"OTHER\":\"BEGIN/COMMIT/ROLLBACK,PREPARED_STATEMENT,CALL_PROCEDURE,KILL,SET_OPTION,CHANGE_DB,UNINSTALL_PLUGIN,INSTALL_PLUGIN,SHUTDOWN,SLAVE_START,SLAVE_STOP,LOCK_TABLES,UNLOCK_TABLES,FLUSH,XA\"}

  • Example normal response
    {
        "keep_days": 7,
        "audit_types": [],
        "all_audit_log_action": "{\"DCL\":\"CREATE_USER,DROP_USER,RENAME_USER,GRANT,REVOKE,ALTER_USER,ALTER_USER_DEFAULT_ROLE\",\"DDL\":\"CREATE,ALTER,DROP,RENAME,TRUNCATE,REPAIR,OPTIMIZE\",\"DML\":\"INSERT,DELETE,UPDATE,REPLACE,SELECT\",\"OTHER\":\"BEGIN/COMMIT/ROLLBACK,PREPARED_STATEMENT,CALL_PROCEDURE,KILL,SET_OPTION,CHANGE_DB,UNINSTALL_PLUGIN,INSTALL_PLUGIN,SHUTDOWN,SLAVE_START,SLAVE_STOP,LOCK_TABLES,UNLOCK_TABLES,FLUSH,XA\"}"
    }
  • Abnormal response

    For details, see Abnormal Response Results.

Status Code

Error Code

For details, see Error Codes.