自 2024 年 10 月 31 日起,Amazon Monitron 將不再開放給新客戶。如果您想要使用 服務,請在該日期之前註冊。現有客戶可以繼續正常使用服務。如需類似 Amazon Monitron 的功能,請參閱我們的部落格文章
本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。
範例:Amazon Monitron 記錄檔項目
追蹤是一種組態,可讓事件以日誌檔的形式傳遞到您指定的 Amazon S3 儲存貯體。 CloudTrail 記錄檔包含一或多個記錄項目。事件代表來自任何來源的單一請求,包括有關請求的操作,動作的日期和時間,請求參數等信息。 CloudTrail 日誌文件不是公共 API 調用的有序堆棧跟踪,因此它們不會以任何特定順序顯示。
下列範例顯示示範專案刪除 (DeleteProject
) 動作的 CloudTrail 記錄項目。
DeleteProject 行動成功
下列範例顯示成功DeleteProject
執行動作後, CloudTrail 記錄檔中可能會顯示的內容。
{ "eventVersion": "1.05", "userIdentity": { "type": "AssumedRole", "principalId": "
principal ID
", "arn": "ARN
", "accountId": "account ID
", "accessKeyId": "access key ID
", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "principal ID
", "arn": "ARN
", "accountId": "account ID
", "userName": "user name
" }, "webIdFederationData": {}, "attributes": { "mfaAuthenticated": "false", "creationDate": "timestamp
" } } }, "eventTime": "timestamp
", "eventSource": "monitron.amazonaws.com", "eventName": "DeleteProject", "awsRegion": "region
", "sourceIPAddress": "source IP address
", "userAgent": "user agent
", "requestParameters": { "Name": "name
" }, "responseElements": { "Name": "name
" }, "requestID": "request ID
", "eventID": "event ID
", "readOnly": false, "eventType": "AwsApiCall", "recipientAccountId": "account ID
" }
失敗的 DeleteProject 動作 (授權錯誤)
下列範例顯示因發生錯誤而失敗的DeleteProject
動作之後, CloudTrail 記錄檔中可能會顯示的內容。在這種情況下,錯誤是授權錯誤,其中用戶沒有權限刪除指定的項目。
{ "eventVersion": "1.05", "userIdentity": { "type": "IAMUser", "principalId": "
principal ID
", "arn": "ARN
", "accountId": "account ID
", "accessKeyId": "access key ID
", "userName": "user name
", "sessionContext": { "sessionIssuer": {}, "webIdFederationData": {}, "attributes": { "mfaAuthenticated": "false", "creationDate": "timestamp
" } } }, "eventTime": "timestamp
", "eventSource": "monitron.amazonaws.com", "eventName": "DeleteProject", "awsRegion": "region
", "sourceIPAddress": "source IP address
", "userAgent": "user agent
", "errorCode": "AccessDenied", "requestParameters": { "Name": "name
" }, "responseElements": { "Message": "User:user ARN
is not authorized to perform: monitron:DeleteProject on resource:resource ARN
" }, "requestID": "request ID
", "eventID": "event ID
", "readOnly": false, "eventType": "AwsApiCall", "recipientAccountId": "account ID
" }
失敗的 DeleteProject 動作 (衝突例外錯誤)
下列範例顯示因發生錯誤而失敗的DeleteProject
動作之後, CloudTrail 記錄檔中可能會顯示的內容。在此情況下,錯誤為衝突例外狀況,當 Amazon Monitron 嘗試刪除專案時,感應器仍然存在。
{ "eventVersion": "1.05", "userIdentity": { "type": "AssumedRole", "principalId": "
principal ID
", "arn": "ARN
", "accountId": "account ID
", "accessKeyId": "access key ID
", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "principal ID
", "arn": "ARN
", "accountId": "account ID
", "userName": "user name
" }, "webIdFederationData": {}, "attributes": { "mfaAuthenticated": "false", "creationDate": "timestamp
" } } }, "eventTime": "timestamp
", "eventSource": "monitron.amazonaws.com", "eventName": "DeleteProject", "awsRegion": "region
", "sourceIPAddress": "source IP address
", "userAgent": "user agent
", "errorCode": "ConflictException", "requestParameters": { "Name": "name
" }, "responseElements": { "message": "This project still has sensors associated to it and cannot be deleted." }, "requestID": "request ID
", "eventID": "event ID
", "readOnly": false, "eventType": "AwsApiCall", "recipientAccountId": "account ID
" }