Configure log storage
KakaoCloud Cloud Trail can store user activity events in Object Storage. The following sections describe how to configure log storage in Cloud Trail.
To configure log storage, you must have both a project role (Project Admin or Project Member) and an organization role (Organization Admin or Trail Viewer).
Enable log storage
Enable log storage to store Cloud Trail event records.
Log storage runs on the selected interval (1 hour or 10 minutes) and begins at the next scheduled time after it is enabled. Storing the logs can take some time.
-
Go to KakaoCloud Console > Management > Cloud Trail.
-
Select the Event menu.
-
Click [Log storage settings] in the upper-right corner of the event list.
-
In the Log storage settings dialog, set Log storage option to Enabled, and then configure the required settings.
Item Description Log storage option Whether to use log storage ( DisabledorEnabled)Event storage scope Project events are stored by default.
- Select Include organization events to store organization events as well.Object Storage bucket Object Storage bucket where events are stored (required)
- Charges apply based on the volume of stored logs.
- Events are stored in thedomain_eventandproject_eventfolders under thetrailfolder in the specified bucket.
- If the bucket is deleted, logs cannot be stored correctly and deleted logs cannot be recovered.File extension Extension of the compressed trail log files stored in the bucket
- Selectgz,gzip, orzip.
- Changes apply from the next log storage time.
- Selectgzto analyze stored logs with Data Catalog and Data Query.Log storage interval Interval for storing logs ( 1 houror10 minutes)
- A folder is created in the bucket every hour, and log files are stored in that folder at the selected interval.IAM access key IAM access key ID and secret access key used to store logs (required)
- To issue an access key ID and secret access key, see Credentials > Issue IAM access key. -
Click [Save].
-
Check whether log storage is enabled to the left of [Log storage settings].
For Cloud Trail log analysis or external system integration after Object Storage delivery, see the following tutorials.
- Query Cloud Trail logs with Data Query: SQL-based event log queries
- Ingest Cloud Trail logs into Splunk Enterprise: External log analysis system integration
Disable log storage
You can stop previously configured log storage. When disabled, all bucket and access key information related to log storage is reset.
- Go to KakaoCloud Console > Management > Cloud Trail.
- Select the Event menu.
- Click [Log storage settings] in the upper-right corner of the event list. In the dialog, set Log storage option to Disabled, and then click [Save].
- In the Disable log storage dialog, click [Stop].