Viewing DWS Console's Operation Logs
Cloud Trace Service (CTS) can record non-query operations on the DWS console to ensure that no invalid or unauthorized operations are performed, enhancing service security management.
Enabling CTS
A tracker will be automatically created after CTS is enabled. All traces recorded by CTS are associated with a tracker. Currently, only one tracker can be created for each account.
- Log in to the CTS console.
- In the navigation pane on the left, choose Tracker List.
- Enable CTS.
If you are a first-time CTS user and do not have any created trackers in the tracker list, enable CTS first. For details, see Enabling CTS in the Cloud Trace Service Getting Started.
If you have enabled CTS, the system has automatically created a management tracker. Only one management tracker can be created and it cannot be deleted. You can also manually create a data tracker. For details, see "Tracker Management" > "Creating a Tracker" in the Cloud Trace Service User Guide.
Viewing Traces
- Log in to the CTS console.
- In the navigation pane on the left, choose Trace List.
- Click the search box above the trace list, set filter criteria, and view the trace.
The following filters are available:
Table 1 Trace parameters Parameter
Description
Trace Name
If you select this option, you also need to specify a trace name.
Trace Source
Select DWS.
Resource Type
Select All resource types or specify a resource type.
Resource Name
If you select this option, you also need to enter a specific resource name.
Resource ID
If you select this option, you also need to select or enter a specific resource ID.
Operator
Select a specific operator (a user rather than a tenant).
Trace ID
If you select this option, you also need to select or enter a specific trace ID.
Trace Status
Select All trace statuses, normal, warning, or incident.
Enterprise Project ID
If you select this option, you also need to select or enter a specific enterprise project ID.
Access Key ID
If you select this option, you also need to select or enter a specific access key ID.
Figure 1 Querying traces
- Click the name of the trace to be viewed. A window is displayed, showing the trace details.
For details about key fields of a CTS trace, see "Trace References" > "Trace Structure" and "Trace References" > "Example Traces" in Cloud Trace Service User Guide.
Disabling the Audit Log Function
If you want to disable the audit log function, disable the tracker in CTS.
- Log in to the CTS console.
- Disable the audit log function by disabling the tracker. To enable the audit log function again, you only need to enable the tracker.
For details about how to enable or disable a tracker, see Disabling or Enabling a Tracker in the Cloud Trace Service User Guide.
Key Operations
With CTS, you can record operations associated with DWS for later query, audit, and backtrack operations. There are many DWS cluster operation events, but the table below only includes some frequently audited operations. The creation and deletion of automated snapshots are not performed by users, therefore not recorded in audit logs.
| Operation | Resource | Event Name |
|---|---|---|
| Creating a cluster | cluster | createCluster |
| Deleting a cluster | cluster | deleteCluster |
| Performing a cluster inspection | cluster | createInspection |
| Stopping an inspection | cluster | AbortInspection |
| Scaling out a cluster | cluster | resizeCluster |
| Increasing the capacity of idle nodes | cluster | resizeWithFreeNodes |
| Performing cluster redistribution | cluster | redistributeCluster |
| Adding disk capacity | cluster | executeDiskExpand |
| Changing cluster flavors | cluster | flavorResize |
| Restarting a cluster | cluster | restartCluster |
| Performing a cluster switchover | cluster | activeStandySwitchover |
| Resetting passwords | cluster | resetClusterPassword |
| Restoring a cluster | cluster | repairCluster |
| Creating a cluster connection | cluster | createClusterConnection |
| Modifying a cluster connection | cluster | modifyClusterConnection |
| Deleting a cluster connection | cluster | deleteClusterConnection |
| Changing all specifications | cluster | resizeCluster |
| Binding or unbinding an EIP | cluster | bindOrUnbindEIP |
| Creating or binding an ELB | cluster | createOrBindElb |
| Unbinding an ELB | cluster | unbindElb |
| Adding a CN | cluster | addCN |
| Deleting a CN | cluster | deleteCN |
| Upgrading a cluster | cluster | clusterUpdateMgr |
| Scaling in a cluster | cluster | shrinkCluster |
| Creating a resource management plan | cluster | addWorkloadPlan |
| Deleting a Resource Pool | cluster | deleteWorkloadQueueInfo |
| Creating a resource pool | cluster | addWorkloadQueueInfo |
| Modifying cluster GUC parameters | cluster | updateClusterConfigurations |
| Removing the read-only status | cluster | cancelReadonly |
| Modifying a maintenance window | cluster | modifyMaintenanceWindow |
| Adding CN nodes in batches | cluster | batchCreateCn |
| Deleting CN nodes in batches | cluster | batchDeleteCn |
| Adding tags in batches | cluster | batchCreateResourceTag |
| Deleting tags in batches | cluster | batchDeleteResourceTag |
| Creating a logical cluster | cluster | createLogicalCluster |
| Deleting logical clusters | cluster | deleteLogicalCluster |
| Editing a logical cluster | cluster | editLogicalCluster |
| Restarting logical clusters | cluster | restartLogicalCluster |
| Converting to a logical cluster | cluster | switchLogicalCluster |
| Starting a cluster | cluster | startCluster |
| Stopping a cluster | cluster | stopCluster |
| Modifying the security group of a cluster | cluster | changeSecurityGroup |
| Changing the cluster time zone | cluster | modifyClusterTimezone |
| Performing a check before cluster creation | cluster | cluster-precheck |
| Performing a redistribution task | cluster | clusterRedistribution |
| Scaling in a cluster | cluster | clusterShrink |
| Applying for a domain name | cluster | createClusterDns |
| Adding a scheduled scaling plan | cluster | createLogicalClusterPlan |
| Creating a public network domain name | cluster | createPublicDnsName |
| Creating a database user | cluster | createUserGrantAuthority |
| Creating a VPC endpoint service | cluster | createVpcEndpointService |
| Deleting a cluster domain name | cluster | deleteClusterDns |
| Deleting a CN | cluster | deleteCN |
| Deleting a database user | cluster | deleteDatabaseUser |
| Deleting a scheduled scaling plan | cluster | deleteLogicalClusterPlan |
| Deleting a public domain name | cluster | deletePublicDnsName |
| Performing operations on an O&M user | cluster | doOmUserOperation |
| Converting an ordinary cluster to an encrypted cluster | cluster | encryptCluster |
| Adding disk capacity | cluster | expandInstanceStorage |
| Preparing for capacity expansion | cluster | expandPrepare |
| Exporting database users | cluster | exportDatabaseUsers |
| Importing user permissions | cluster | importUserAuthority |
| Modifying a cluster domain name | cluster | modifyClusterDns |
| Modifying a public network domain name | cluster | modifyDnsName |
| Rotating a key | cluster | rotateKey |
| Checking scale-in | cluster | shrinkCheck |
| Scaling in a logical cluster | cluster | shrinkLogicalCluster |
| Starting an instance | cluster | startInstance |
| Stopping an instance | cluster | stopInstance |
| Stopping cluster tuning | cluster | stopTuningCluster |
| Starting or stopping a scheduled scaling plan | cluster | switchLogicalClusterPlan |
| Performing a switchback | cluster | switchover |
| Synchronizing an IAM user | cluster | syncIamUserToDatabase |
| Tuning a cluster | cluster | tuningCluster |
| Updating the node alias | cluster | updateInstanceAliasName |
| Editing a scheduled scaling plan | cluster | updateLogicalClusterPlan |
| Updating database user permissions | cluster | updateUserAuthority |
| Restoring a cluster | cluster | restoreCluster |
| Updating a snapshot policy | cluster | updateClustersBackupPolicy |
| Updating the status of a resource pool | cluster | updateWorkloadStatus |
| Operation | Resource | Event |
|---|---|---|
| Creating a snapshot | backup | createBackup |
| Deleting a snapshot | backup | deleteBackup |
| Copying snapshots | backup | copySnapshot |
| Deleting a snapshot policy | backup | deleteBackupPolicy |
| Deleting a cross-region snapshot configuration | backup | deleteCrossRegionSnapshotPolicy |
| Modifying snapshot configuration | backup | updateSnapshotConfig |
| Operation | Resource | Event |
|---|---|---|
| Creating a DR task | disasterRecovery | createDisasterRecovery |
| Deleting a DR task | disasterRecovery | deleteDisasterRecovery |
| Starting a DR task | disasterRecovery | startDisasterRecoveryAction |
| Stopping a DR task | disasterRecovery | stopDisasterRecoveryAction |
| Switching to the DR cluster | disasterRecovery | switchoverDisasterRecoveryAction |
| Performing an exception switchover | disasterRecovery | failoverDisasterRecoveryAction |
| Performing DR | disasterRecovery | recoveryDisaster |
| Updating DR configurations | disasterRecovery | updateRecoveryDisaster |
| Operation | Resource | Event |
|---|---|---|
| Creating a bucket folder | migration | createBucketFolder |
| Creating a resource tenant bucket | migration | createResTenantBucket |
| Creating a job | migration | dataMigrationCreateApplication |
| Creating an instance | migration | dataMigrationCreateCluster |
| Creating a connection | migration | dataMigrationCreateConnection |
| Creating a mapping | migration | dataMigrationCreateMapping |
| Creating an OBS migration job | migration | dataMigrationCreateOBSMigrationTask |
| Creating an OBS migration group | migration | dataMigrationCreateOBSMigrationTaskGroup |
| Deleting a job | migration | dataMigrationDeleteApplication |
| Deleting an instance | migration | dataMigrationDeleteCluster |
| Deleting a connection | migration | dataMigrationDeleteConnection |
| Deleting a mapping | migration | dataMigrationDeleteMapping |
| Deleting an OBS migration job | migration | dataMigrationDeleteOBSMigrationTask |
| Deleting an OBS migration job group | migration | dataMigrationDeleteOBSMigrationTaskGroup |
| Testing a connection | migration | dataMigrationDialsConnection |
| Modifying a connection | migration | dataMigrationModifyConnection |
| Modifying a mapping | migration | dataMigrationModifyMapping |
| Starting a job | migration | dataMigrationStartApplication |
| Starting an OBS migration job | migration | dataMigrationStartOBSMigrationTask |
| Starting an OBS migration job group | migration | dataMigrationStartOBSMigrationTaskGroup |
| Stopping a job | migration | dataMigrationStopApplication |
| Stopping an OBS migration job | migration | dataMigrationStopOBSMigrationTask |
| Stopping an OBS migration job group | migration | dataMigrationStopOBSMigrationTaskGroup |
| Operation | Resource | Event |
|---|---|---|
| Creating an extended data source | dataSource | createExtDataSource |
| Deleting an extended data source | dataSource | deleteExtDataSource |
| Updating an extended data source | dataSource | updateExtDataSource |
| Creating an external data source | dataSource | configureExtDataResource |
| Deleting an external data source | dataSource | deleteExtDataSources |
| Updating the external data source configuration | dataSource | reconfigureExtDataSources |
| Operation | Resource | Event |
|---|---|---|
| Setting security parameters | configurations | updateConfigurations |
| Operation | Resource | Event |
|---|---|---|
| Deleting objects in a bucket | bucket | deleteBucketObjects |
| Deleting fragments in a bucket | bucket | deleteMultipartFile |
| Deleting a resource tenant bucket | bucket | deleteRsTenantBucket |
| Configuring bucket encryption | bucket | setBucketEncryption |
| Configuring a bucket lifecycle | bucket | setBucketLifecycle |
| Configuring a bucket policy | bucket | setResTenantBucketPolicy |
| Operation | Resource | Event |
|---|---|---|
| Restoring an instance | instance | clusterRepair |
| Deleting a node | instance | deleteNode |
| Operation | Resource | Event |
|---|---|---|
| Performing operations on a SQL filter rule | workload | wlmBlockRuleOperate |
| Performing resource management operations | workload | wlmOperate |
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot