Updated on 2026-08-25 GMT+08:00

Setting SQL Audit

Function

This API is used to set a policy for SQL audit logs.

Authorization Information

Each account has all the permissions required to call all APIs, but IAM users must be assigned the required permissions.
  • If you are using role/policy-based authorization, see Permissions and Supported Actions for details on the required permissions.
  • If you are using identity policy-based authorization, the following identity policy-based permissions are required.

Action

Access Level

Resource Type (*: required)

Condition Key

Alias

Dependencies

rds:auditlog:operate

permission_management

instance

g:EnterpriseProjectId

g:ResourceTag/<tag-key>

-

-

Constraints

This API is available only to RDS for MySQL and RDS for PostgreSQL.

URI

  • URI format

    PUT /v3/{project_id}/instances/{instance_id}/auditlog-policy

  • Parameter description
    Table 1 Parameters

    Parameter

    Mandatory

    Description

    project_id

    Yes

    Definition

    Project ID of a tenant in a region.

    To obtain the value, see Obtaining a Project ID.

    Constraints

    N/A

    Range

    N/A

    Default Value

    N/A

    instance_id

    Yes

    Definition

    Instance ID.

    You can obtain the value of this parameter from id in Table 4 by calling the API for querying DB instances.

    Constraints

    N/A

    Range

    N/A

    Default Value

    N/A

Request

Table 2 Parameters

Parameter

Mandatory

Type

Description

keep_days

Yes

Integer

Definition

Number of days for storing audit logs.

Constraints

N/A

Range

  • 0: indicates that SQL audit is disabled.
  • 1 to 3660: indicates the retention days for audit logs after SQL audit is enabled.

Default Value

N/A

reserve_auditlogs

No

Boolean

Definition

Whether to retain historical audit logs when SQL audit is disabled.

Constraints

This parameter is valid only when SQL audit is disabled.

Range

  • true: Historical audit logs will be reserved for some time when SQL audit is disabled.
  • false: Historical audit logs will be deleted immediately when SQL audit is disabled.

Default Value

true

audit_types

No

Array of strings

Definition

Operation types that can be recorded in audit logs.

Constraints

  • This parameter is valid only when SQL audit is enabled.
  • This parameter is only available for RDS for MySQL instances.

Range

  • If this parameter is left blank, all operation types will be recorded.
  • The following operation types can be recorded:
    • Supported DCL operations: CREATE_USER, DROP_USER, RENAME_USER, GRANT, REVOKE, ALTER_USER, and ALTER_USER_DEFAULT_ROLE
    • Supported DDL operations: CREATE, ALTER, DROP, RENAME, TRUNCATE, REPAIR, and OPTIMIZE
    • Supported DML operations: INSERT, DELETE, UPDATE, REPLACE, and SELECT
    • Supported other operations: BEGIN/COMMIT/ROLLBACK, PREPARED_STATEMENT, CALL_PROCEDURE, KILL, SET_OPTION, CHANGE_DB, UNINSTALL_PLUGIN, UNINSTALL_PLUGIN, INSTALL_PLUGIN, SHUTDOWN, SLAVE_START, SLAVE_STOP, LOCK_TABLES, UNLOCK_TABLES, FLUSH, and XA

Default Value

If this parameter is left blank, all operation types will be recorded.

Example Request

  • Enable SQL Audit and set the audit log retention period to 5 days.
    PUT https://{endpoint}/v3/0483b6b16e954cb88930a360d2c4e663/instances/cee5265e1e5845649e354841234567dfin01/auditlog-policy
    
    {
        "keep_days":5,
        "audit_types": [
        "CREATE_USER"
        ]
    }
  • Disable SQL Audit and delete existing historical audit logs.
    {
        "keep_days":0,
        "reserve_auditlogs":false
    }

Response

  • Normal response
    Table 3 Parameters

    Parameter

    Type

    Description

    status

    String

    Definition

    Result of setting SQL audit.

    Range

    COMPLETED: successful

  • Example normal response
    {
      "status":"COMPLETED"
    }
  • Abnormal response

    For details, see Abnormal Response Results.

Status Code

Error Code

For details, see Error Codes.