Ensure that you have an alert monitoring rule and an alert configured to trigger a notification alarm whenever an unauthorized API call is made within your Alibaba Cloud account. Your alert monitoring rule should query ActionTrail logs for unauthorized API calls that throw errors such as "Forbidden", "NoPermission", "DeleteRouteEntry", "InvalidAccessKeyId", and "InvalidSecurityToken".
Using Simple Log Service (SLS) alerts to detect unauthorized API calls helps prevent accidental or intentional modifications that could lead to unauthorized access or other security breaches. Real-time monitoring ensures timely response, mitigating potential risks and safeguarding your libaba Cloud infrastructure effectively.
Audit
To dentify if an SLS alert exists and is configured correctly to monitor unauthorized API calls within your Alibaba Cloud account, perform the following operations:
Checking for Simple Log Service (SLS) alerts via Alibaba Cloud CLI (aliyun) is not currently supported.Remediation / Resolution
To ensure that a Simple Log Service (SLS) alert exists for detecting unauthorized API calls, perform the following operations:
Creating and managing Simple Log Service (SLS) alerts via Alibaba Cloud CLI (aliyun) is not currently supported.