Console Audit Logging
TiDB Cloud provides the console audit logging feature to help you track various behaviors and operations of users on the TiDB Cloud console. For example, you can track operations, such as inviting a user to join your organization and importing data.
Prerequisites
- You must be in the
Organization OwnerorOrganization Console Audit Managerrole of your organization in TiDB Cloud. Otherwise, you cannot see the console audit logging-related options in the TiDB Cloud console.
Enable console audit logging
The console audit logging feature is disabled by default. After you enable it, all supported event types in the TiDB Cloud console are audited, and you cannot configure it to audit only specific event types. To enable it, take the following steps:
- In the TiDB Cloud console, switch to your target organization using the combo box in the upper-left corner.
- In the left navigation pane, click Console Audit Logging.
- Click Settings in the upper-right corner, enable console audit logging, and then click Update.
Disable console audit logging
To disable console audit logging, take the following steps:
- In the TiDB Cloud console, switch to your target organization using the combo box in the upper-left corner.
- In the left navigation pane, click Console Audit Logging.
- Click Settings in the upper-right corner, disable console audit logging, and then click Update.
View console audit logs
You can only view the console audit logs of your organization.
- In the TiDB Cloud console, switch to your target organization using the combo box in the upper-left corner.
- In the left navigation pane, click Console Audit Logging.
- To get a specific part of audit logs, you can filter the event type, operation status, and time range.
- (Optional) To filter more fields, click Advanced filter, add more filters, and then click Apply.
- Click the row of a log to view its detailed information in the right pane.
Export console audit logs
To export the console audit logs of your organization, take the following step:
- In the TiDB Cloud console, switch to your target organization using the combo box in the upper-left corner.
- In the left navigation pane, click Console Audit Logging.
- (Optional) If you need to export a specific part of console audit logs, you can filter through various conditions. Otherwise, skip this step.
- Click Download logs and select the desired export format in JSON or CSV.
Console audit log storage policy
The storage time of console audit logs is 90 days, after which the logs will be automatically cleaned up.
Console audit log integrity and access control
To help you meet regulatory compliance requirements, TiDB Cloud provides the following controls for console audit logging:
Completeness: When console audit logging is enabled for your organization, the audit system records user operations that trigger the supported event types. Log entries are typically available for viewing, download, and programmatic access via the API within 60 minutes of the event occurrence.
Access control: Only users with the
Organization OwnerorOrganization Console Audit Managerrole in your organization can manage console audit logging for your organization. Other organization members cannot enable or disable audit logging or modify log settings.
Console audit event types
The console audit logs record various user activities on the TiDB Cloud console through event types.
Console audit log fields
To help you track user activities, TiDB Cloud provides the following fields for each console audit log: