工作负载位置 |
块存储 |
审核日志源 |
块存储 |
接受审核的操作示例 |
创建卷
包含审核信息的日志条目中的字段 | ||
---|---|---|
审核元数据 | 审核字段名称 | 值 |
用户或服务身份 | message.user.identity |
例如,
"message":"{"user":{"identity":"root-admin-client-cert"}} |
目标 (调用 API 的字段和值) |
message.action |
例如,
"message":"{"action":"volume-create"}" |
操作 (包含所执行操作的字段) |
action
|
例如,
|
活动时间戳 |
time
|
例如,
|
操作来源 | message.sourceIPs |
例如, "message":"{"sourceIPs":["10.252.143.2"]}" |
结果 | message.response |
例如, "message":"{"response":"success"}" |
其他字段 | 不适用 |
不适用 |
日志示例
{
"pri":"14",
"time":"2022-12-07T13:46:49.133781Z",
"host":"storage",
"ident":"storage",
"pid":"-",
"msgid":"-",
"extradata":"-",
"message":"{"time":"2022-12-07T13:40:18Z","auditID":"90199274229","user":{"identity":"root-admin-client-cert"},"resource":"{"Application":"ontapi","Hostname":"zh-ad-stge02-02","StorageVirtualMachine":"root-admin"}","action":"volume-create","sourceIPs":["10.252.143.2"],"response":"success","_gdch_org":"root-admin"}",
"_gdch_cluster":"root-admin",
"_gdch_fluentbit_pod":"anthos-audit-logs-forwarder-vn8f9",
"_gdch_service_name":"admin-audit-logs"
}
设置卷的大小
包含审核信息的日志条目中的字段 | ||
---|---|---|
审核元数据 | 审核字段名称 | 值 |
用户或服务身份 | message.user.identity |
例如,
"message":"{"user":{"identity":"root-admin-client-cert"}} |
目标 (调用 API 的字段和值) |
message.action |
例如,
"message":"{"action":"volume-size"}" |
操作 (包含所执行操作的字段) |
action
|
例如,
|
活动时间戳 |
time
|
例如,
|
操作来源 | message.sourceIPs |
例如, "message":"{"sourceIPs":["10.252.143.2"]}" |
结果 | message.response |
例如, "message":"{"response":"success"}" |
其他字段 | 不适用 |
不适用 |
日志示例
{
"pri":"14",
"time":"2022-12-07T13:46:49.135968Z",
"host":"storage",
"ident":"storage",
"pid":"-",
"msgid":"-",
"extradata":"-",
"message":"{"time":"2022-12-07T13:46:36Z","auditID":"120264072202","user":{"identity":"root-admin-client-cert"},"resource":"{"Application":"ontapi","Hostname":"zh-ad-stge03-01","StorageVirtualMachine":"root-admin"}","action":"volume-size","sourceIPs":["10.252.143.2"],"response":"success","_gdch_org":"root-admin"}",
"_gdch_cluster":"root-admin",
"_gdch_fluentbit_pod":"anthos-audit-logs-forwarder-vn8f9",
"_gdch_service_name":"admin-audit-logs"
}
删除卷
包含审核信息的日志条目中的字段 | ||
---|---|---|
审核元数据 | 审核字段名称 | 值 |
用户或服务身份 | message.user.identity |
例如,
"message":"{"user":{"identity":"root-admin-client-cert"}} |
目标 (调用 API 的字段和值) |
message.action |
例如,
"message":"{"action":"volume-destroy"}" |
操作 (包含所执行操作的字段) |
action
|
例如,
|
活动时间戳 |
time
|
例如,
|
操作来源 | message.sourceIPs |
例如, "message":"{"sourceIPs":["10.252.143.2"]}" |
结果 | message.response |
例如, "message":"{"response":"success"}" |
其他字段 | 不适用 |
不适用 |
日志示例
{
"pri":"14",
"time":"2022-12-07T13:46:49.136236Z",
"host":"storage",
"ident":"storage",
"pid":"-",
"msgid":"-",
"extradata":"-",
"message":"{"time":"2022-12-07T13:46:37Z","auditID":"90203137689","user":{"identity":"root-admin-client-cert"},"resource":"{"Application":"ontapi","Hostname":"zh-ad-stge01-02","StorageVirtualMachine":"root-admin"}","action":"volume-destroy","sourceIPs":["10.252.143.2"],"response":"success","_gdch_org":"root-admin"}",
"_gdch_cluster":"root-admin",
"_gdch_fluentbit_pod":"anthos-audit-logs-forwarder-vn8f9",
"_gdch_service_name":"admin-audit-logs"
}