Updated on 2023-03-07 GMT+08:00

Enabling CTS

CTS records operations performed on cloud resources in your account. The operation logs can be used to perform security analysis, track resource changes, perform compliance audits, and locate faults.

It is recommended that you enable the CTS service to record key IAM operations, such as creating and deleting users.

Procedure

  1. Log in to the management console.
  2. Click Service List and choose Management & Deployment > Cloud Trace Service.
  3. Click Trackers in the navigation pane.
  4. Click Enable CTS.
  5. In the displayed dialog box, click Enable. The system automatically creates a tracker.

    After you enable CTS, you can view the tracker information on the Trackers page.

CTS records all operations performed on IAM, such as creating users and user groups. Table 1 shows the IAM operations that can be recorded by CTS.
Table 1 IAM operations that can be recorded by CTS

Operation

Resource Type

Trace Name

Login

user

login

Logging in as a user of the Cloud Alliance

user

cloudLoginBySaml

Login failure

user

loginFailed

Logout

user

logout

Logging in as a federated user

user

tenantLoginBySamlSuccess/

oidcLoginSuccess

(IAM user) Changing the password at first login, when the password will expire, or after the password expires

user

changePassword

Creating a user

user

createUser

Modifying user information

user

updateUser

Deleting a user

user

deleteUser

Creating an access key (AK/SK)

user

createCredential and addCredential

Deleting an access key (AK/SK)

user

deleteCredential

Disabling or enabling an access key (AK/SK)

user

changeCredentialStatus

Modifying an access key (AK/SK)

user

updateCredential

Changing the email address

user

modifyUserEmail

Changing the mobile number

user

modifyUserMobile

Changing the password

user

modifyUserPassword

Setting a password for a user (by the administrator)

user

setPasswordByAdmin

Creating a user group

userGroup

createUserGroup

Modifying a user group

userGroup

updateGroup and updateUserGroup

Deleting a user group

userGroup

deleteUserGroup

Adding users to a user group

userGroup

addUserToGroup and updateUser/updateUserGroup

Removing users from a user group

userGroup

removeUserFromGroup and updateUser/updateUserGroup

Creating a project

project

createProject

Modifying a project

project

updateProject

Deleting a project

project

deleteProject

Creating an agency

agency

createAgency

Modifying an agency

agency

updateAgency

Deleting an agency

agency

deleteAgency

Switching roles

agency

switchRole

Token

createToken

Creating an identity provider

identityProvider

createIdentityProvider

Modifying an identity provider

identityProvider

updateIdentityProvider

Deleting an identity provider

identityProvider

deleteIdentityProvider

Uploading IdP metadata

identityProvider

updateMetaConfigure and uploadMetadataFile

Editing IdP metadata

identityProvider

updateMetaConfigure

Creating a custom policy

role

createRole

Modifying a custom policy

role

updateRole

Deleting a custom policy

role

deleteRole

Modifying the login authentication policy

domain

updateSecurityPolicies

Modifying the password policy

domain

updatePasswordPolicies

Modifying the ACL

domain

updateACLPolicies