Description
Restricting ActionTrail regions or event types can leave required activity outside the audit scope. Check both collection coverage and actual log delivery.
Potential impact
- Records needed to investigate changes in other regions or required read and write activity may be missing.
- Determining an incident’s cause and scope or meeting retention requirements can become harder.
Remediation
Set trail_region and event_rw to All when all regions and read and write events are required. Configure the OSS or Simple Log Service destination and permissions, then verify trail activation, actual log delivery and retention.
Examples
These excerpts compare region coverage for an OSS destination. Supply the actual bucket name and the ARN of a role with the required write permissions.
Before
resource "alicloud_actiontrail_trail" "actiontrail" {
trail_name = "action-trail"
oss_write_role_arn = var.oss_write_role_arn
oss_bucket_name = var.oss_bucket_name
event_rw = "All"
trail_region = "cn-hangzhou"
}
After
resource "alicloud_actiontrail_trail" "actiontrail" {
trail_name = "action-trail"
oss_write_role_arn = var.oss_write_role_arn
oss_bucket_name = var.oss_bucket_name
event_rw = "All"
trail_region = "All"
}
The after example expands regional coverage of supported read and write events to All. It does not automatically include every service’s data-access logs; check support for the event types you need.