Updated on 2022-11-23 GMT+08:00

Audit and Monitoring

Cloud Trace Service (CTS) records operations performed on cloud resources in your account. The operation logs can be used to perform security analysis, track resource changes, perform compliance audits, and locate faults.

For details about IAM operations that can be recorded by CTS, see "IAM operations that can be recorded by CTS" in Enabling CTS. After you enable CTS and create and configure a tracker, CTS starts to record operations for auditing. For details, see Enabling CTS. After CTS is enabled, you can view IAM audit logs. CTS stores operation logs of the last seven days.

CTS allows you to configure key event notifications. You can add IAM-related high-risk and sensitive operations as key operations to the real-time monitoring list of CTS for monitoring and tracing. If a key operation in the monitoring list is triggered when a user uses the IAM service, CTS records the operation log and sends a notification to the related subscriber in real time.