Review Alibaba Cloud ActionTrail log coverage

Include the required regions and read and write events in audit logs.

Description

Restricting ActionTrail regions or event types can leave required activity outside the audit scope. Check both collection coverage and actual log delivery.

Potential impact

  • Records needed to investigate changes in other regions or required read and write activity may be missing.
  • Determining an incident’s cause and scope or meeting retention requirements can become harder.

Remediation

Set trail_region and event_rw to All when all regions and read and write events are required. Configure the OSS or Simple Log Service destination and permissions, then verify trail activation, actual log delivery and retention.

Examples

These excerpts compare region coverage for an OSS destination. Supply the actual bucket name and the ARN of a role with the required write permissions.

Before

hcl
resource "alicloud_actiontrail_trail" "actiontrail" {
  trail_name         = "action-trail"
  oss_write_role_arn = var.oss_write_role_arn
  oss_bucket_name    = var.oss_bucket_name
  event_rw           = "All"
  trail_region       = "cn-hangzhou"
}

After

hcl
resource "alicloud_actiontrail_trail" "actiontrail" {
  trail_name         = "action-trail"
  oss_write_role_arn = var.oss_write_role_arn
  oss_bucket_name    = var.oss_bucket_name
  event_rw           = "All"
  trail_region       = "All"
}

The after example expands regional coverage of supported read and write events to All. It does not automatically include every service’s data-access logs; check support for the event types you need.

References