Console Audit Logging
TiDB Cloud provides the console audit logging feature to help you track various behaviors and operations of users on the TiDB Cloud console. For example, you can track operations, such as inviting a user to join your organization and creating a cluster.
Prerequisites
- You must be in the Owner or Audit Admin role of your organization in TiDB Cloud. Otherwise, you cannot see the console audit logging-related options in the TiDB Cloud console. The Audit Admin role is only visible upon request, so it is recommended that you use the Owner role directly. If you need to use the Audit Admin role, click Help in the lower-right corner of the TiDB Cloud console, fill in "Apply for the Audit Admin role" in the Description field, and then click Send. For more information about roles in TiDB Cloud, see Manage role access.
- You can only enable and disable the console audit logging for your organization. You can only track the actions of users in your organization.
- After the console audit logging is enabled, all event types of the TiDB Cloud console will be audited, and you cannot specify only auditing some of them.
Enable console audit logging
The console audit logging feature is disabled by default. To enable it, take the following steps:
- In the upper-right corner of the TiDB Cloud console, click Organization > Console Audit Logging.
- If it is the first time your organization enables console audit logging, click Enable Console Audit Logging. Otherwise, click Setting in the upper-right corner to enable console audit logging.
Disable console audit logging
To disable console audit logging, take the following steps:
- In the upper-right corner of the TiDB Cloud console, click Organization > Console Audit Logging.
- Click Setting in the upper-right corner, and then disable console audit logging.
View console audit logs
You can only view the console audit logs of your organization.
- In the upper-right corner of the TiDB Cloud console, click Organization > Console Audit Logging.
- To get a specific part of audit logs, you can filter the event type, operation status, and time range.
- (Optional) To filter more fields, click Advanced filter, add more filters, and then click Apply.
- Click the row of a log to view its detailed information in the right pane.
Export console audit logs
To export the console audit logs of your organization, take the following step:
- In the upper-right corner of the TiDB Cloud console, click Organization > Console Audit Logging.
- (Optional) If you need to export a specific part of console audit logs, you can filter through various conditions. Otherwise, skip this step.
- Click Export and select the desired export format in JSON or CSV.
Console audit log storage policy
The storage time of console audit logs is 90 days, after which the logs will be automatically cleaned up.
Console audit event types
The console audit logs record various user activities on the TiDB Cloud console through event types.
Console audit log fields
To help you track user activities, TiDB Cloud provides the following fields for each console audit log: