Amazon Monitron 不再向新客戶開放。現有客戶可以繼續正常使用服務。如需類似 Amazon Monitron 的功能,請參閱我們的部落格文章
本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。
追蹤是一種組態,能讓事件以日誌檔案的形式交付到您指定的 Amazon S3 儲存貯體。CloudTrail 日誌檔案包含一或多個日誌專案。一個事件為任何來源提出的單一請求,並包含請求動作、請求的日期和時間、請求參數等資訊。CloudTrail 日誌檔並非依公有 API 呼叫的堆疊追蹤排序,因此不會以任何特定順序出現。
下列範例顯示示範專案刪除 (DeleteProject
) 動作的 CloudTrail 日誌項目。
DeleteProject 動作成功
下列範例顯示成功DeleteProject
動作後CloudTrail 日誌中可能出現的內容。
{
"eventVersion": "1.05",
"userIdentity": {
"type": "AssumedRole",
"principalId": "principal ID
",
"arn": "ARN
",
"accountId": "account ID
",
"accessKeyId": "access key ID
",
"sessionContext": {
"sessionIssuer": {
"type": "Role",
"principalId": "principal ID
",
"arn": "ARN
",
"accountId": "account ID
",
"userName": "user name
"
},
"webIdFederationData": {},
"attributes": {
"mfaAuthenticated": "false",
"creationDate": "timestamp
"
}
}
},
"eventTime": "timestamp
",
"eventSource": "monitron.amazonaws.com",
"eventName": "DeleteProject",
"awsRegion": "region
",
"sourceIPAddress": "source IP address
",
"userAgent": "user agent
",
"requestParameters": {
"Name": "name
"
},
"responseElements": {
"Name": "name
"
},
"requestID": "request ID
",
"eventID": "event ID
",
"readOnly": false,
"eventType": "AwsApiCall",
"recipientAccountId": "account ID
"
}
DeleteProject 動作失敗 (授權錯誤)
下列範例顯示由於發生錯誤而失敗DeleteProject
的動作後CloudTrail 日誌中可能會出現的內容。在此情況下,錯誤是授權錯誤,使用者沒有刪除指定專案的許可。
{
"eventVersion": "1.05",
"userIdentity": {
"type": "IAMUser",
"principalId": "principal ID
",
"arn": "ARN
",
"accountId": "account ID
",
"accessKeyId": "access key ID
",
"userName": "user name
",
"sessionContext": {
"sessionIssuer": {},
"webIdFederationData": {},
"attributes": {
"mfaAuthenticated": "false",
"creationDate": "timestamp
"
}
}
},
"eventTime": "timestamp
",
"eventSource": "monitron.amazonaws.com",
"eventName": "DeleteProject",
"awsRegion": "region
",
"sourceIPAddress": "source IP address
",
"userAgent": "user agent
",
"errorCode": "AccessDenied",
"requestParameters": {
"Name": "name
"
},
"responseElements": {
"Message": "User: user ARN
is not authorized to perform: monitron:DeleteProject on resource: resource ARN
"
},
"requestID": "request ID
",
"eventID": "event ID
",
"readOnly": false,
"eventType": "AwsApiCall",
"recipientAccountId": "account ID
"
}
DeleteProject 動作失敗 (衝突例外狀況錯誤)
下列範例顯示由於發生錯誤而失敗DeleteProject
的動作後CloudTrail 日誌中可能會出現的內容。在此情況下,錯誤是衝突例外狀況,其中當 Amazon Monitron 嘗試刪除專案時,感應器仍然存在。
{
"eventVersion": "1.05",
"userIdentity": {
"type": "AssumedRole",
"principalId": "principal ID
",
"arn": "ARN
",
"accountId": "account ID
",
"accessKeyId": "access key ID
",
"sessionContext": {
"sessionIssuer": {
"type": "Role",
"principalId": "principal ID
",
"arn": "ARN
",
"accountId": "account ID
",
"userName": "user name
"
},
"webIdFederationData": {},
"attributes": {
"mfaAuthenticated": "false",
"creationDate": "timestamp
"
}
}
},
"eventTime": "timestamp
",
"eventSource": "monitron.amazonaws.com",
"eventName": "DeleteProject",
"awsRegion": "region
",
"sourceIPAddress": "source IP address
",
"userAgent": "user agent
",
"errorCode": "ConflictException",
"requestParameters": {
"Name": "name
"
},
"responseElements": {
"message": "This project still has sensors associated to it and cannot be deleted."
},
"requestID": "request ID
",
"eventID": "event ID
",
"readOnly": false,
"eventType": "AwsApiCall",
"recipientAccountId": "account ID
"
}