块存储 (BLOCK)

工作负载位置

块存储

审核日志源

块存储

接受审核的操作示例

创建卷

包含审核信息的日志条目中的字段
审核元数据 审核字段名称
用户或服务身份 message.user.identity 例如,

"message":"{"user":{"identity":"root-admin-client-cert"}}

目标

(调用 API 的字段和值)

message.action 例如,

"message":"{"action":"volume-create"}"

操作

(包含所执行操作的字段)

action

例如,

"action":"volume-create"

活动时间戳 time

例如,

"time":"2022-12-07T13:46:49.133781Z"

操作来源 message.sourceIPs

例如,

"message":"{"sourceIPs":["10.252.143.2"]}"

结果 message.response

例如,

"message":"{"response":"success"}"

其他字段 不适用

不适用

日志示例

{
  "pri":"14",
  "time":"2022-12-07T13:46:49.133781Z",
  "host":"storage",
  "ident":"storage",
  "pid":"-",
  "msgid":"-",
  "extradata":"-",
  "message":"{"time":"2022-12-07T13:40:18Z","auditID":"90199274229","user":{"identity":"root-admin-client-cert"},"resource":"{"Application":"ontapi","Hostname":"zh-ad-stge02-02","StorageVirtualMachine":"root-admin"}","action":"volume-create","sourceIPs":["10.252.143.2"],"response":"success","_gdch_org":"root-admin"}",
  "_gdch_cluster":"root-admin",
  "_gdch_fluentbit_pod":"anthos-audit-logs-forwarder-vn8f9",
  "_gdch_service_name":"admin-audit-logs"
}

设置卷的大小

包含审核信息的日志条目中的字段
审核元数据 审核字段名称
用户或服务身份 message.user.identity 例如,

"message":"{"user":{"identity":"root-admin-client-cert"}}

目标

(调用 API 的字段和值)

message.action 例如,

"message":"{"action":"volume-size"}"

操作

(包含所执行操作的字段)

action

例如,

"action":"volume-size"

活动时间戳 time

例如,

"time":"2022-12-07T13:46:49.133781Z"

操作来源 message.sourceIPs

例如,

"message":"{"sourceIPs":["10.252.143.2"]}"

结果 message.response

例如,

"message":"{"response":"success"}"

其他字段 不适用

不适用

日志示例

{
  "pri":"14",
  "time":"2022-12-07T13:46:49.135968Z",
  "host":"storage",
  "ident":"storage",
  "pid":"-",
  "msgid":"-",
  "extradata":"-",
  "message":"{"time":"2022-12-07T13:46:36Z","auditID":"120264072202","user":{"identity":"root-admin-client-cert"},"resource":"{"Application":"ontapi","Hostname":"zh-ad-stge03-01","StorageVirtualMachine":"root-admin"}","action":"volume-size","sourceIPs":["10.252.143.2"],"response":"success","_gdch_org":"root-admin"}",
  "_gdch_cluster":"root-admin",
  "_gdch_fluentbit_pod":"anthos-audit-logs-forwarder-vn8f9",
  "_gdch_service_name":"admin-audit-logs"
}

删除卷

包含审核信息的日志条目中的字段
审核元数据 审核字段名称
用户或服务身份 message.user.identity 例如,

"message":"{"user":{"identity":"root-admin-client-cert"}}

目标

(调用 API 的字段和值)

message.action 例如,

"message":"{"action":"volume-destroy"}"

操作

(包含所执行操作的字段)

action

例如,

"action":"volume-destroy"

活动时间戳 time

例如,

"time":"2022-12-07T13:46:49.133781Z"

操作来源 message.sourceIPs

例如,

"message":"{"sourceIPs":["10.252.143.2"]}"

结果 message.response

例如,

"message":"{"response":"success"}"

其他字段 不适用

不适用

日志示例

{
  "pri":"14",
  "time":"2022-12-07T13:46:49.136236Z",
  "host":"storage",
  "ident":"storage",
  "pid":"-",
  "msgid":"-",
  "extradata":"-",
  "message":"{"time":"2022-12-07T13:46:37Z","auditID":"90203137689","user":{"identity":"root-admin-client-cert"},"resource":"{"Application":"ontapi","Hostname":"zh-ad-stge01-02","StorageVirtualMachine":"root-admin"}","action":"volume-destroy","sourceIPs":["10.252.143.2"],"response":"success","_gdch_org":"root-admin"}",
  "_gdch_cluster":"root-admin",
  "_gdch_fluentbit_pod":"anthos-audit-logs-forwarder-vn8f9",
  "_gdch_service_name":"admin-audit-logs"
}