Ensure that your ActionTrail trails are recording global, multi-region events in order to increase the visibility of the API activity in your Alibaba Cloud account for security and management purposes.
ActionTrail's API call history supports security analysis, resource tracking, and compliance auditing. A multi-regions trail is essential for detecting unexpected activities in unused regions. Enabling Global Service Logging by default ensures event recording for Alibaba Cloud global services in a multi-regions trail. This guarantees the capture of management operations on all resources within an Alibaba Cloud account.
Audit
To determine if your ActionTrail trail is enabled for all supported regions, perform the following operations:
Remediation / Resolution
To ensure that at least one ActionTrail trail is configured to record global, multi-region events within your Alibaba Cloud account, perform the following operations:
References
- Alibaba Cloud Documentation
- What is ActionTrail?
- Single-account trail overview
- Services that work with ActionTrail
- Supported regions
- Alibaba Cloud CLI Documentation
- DescribeTrails
- UpdateTrail