View a markdown version of this page

了解 Wickr 日誌檔案項目 - AWS Wickr

本指南記載於 2025 年 3 月 13 日發行的新 AWS Wickr 管理主控台。如需 AWS Wickr 管理主控台傳統版本的文件,請參閱傳統管理指南

本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。

了解 Wickr 日誌檔案項目

追蹤是一種組態,能讓事件以日誌檔案的形式交付到您指定的 Amazon S3 儲存貯體。CloudTrail 日誌檔案包含一或多個日誌專案。一個事件為任何來源提出的單一請求,並包含請求動作、請求的日期和時間、請求參數等資訊。CloudTrail 日誌檔並非依公有 API 呼叫的堆疊追蹤排序,因此不會以任何特定順序出現。

以下範例顯示的是展示 CreateAdminSession 動作的 CloudTrail 日誌項目。

{ "eventVersion": "1.08", "userIdentity": { "type": "AssumedRole", "principalId": "<principal-id>", "arn": "<arn>", "accountId": "<account-id>", "accessKeyId": "<access-key-id>", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "<principal-id>", "arn": "<arn>", "accountId": "<account-id>", "userName": "<user-name>" }, "webIdFederationData": {}, "attributes": { "creationDate": "2023-03-10T07:53:17Z", "mfaAuthenticated": "false" } } }, "eventTime": "2023-03-10T08:19:24Z", "eventSource": "wickr.amazonaws.com", "eventName": "CreateAdminSession", "awsRegion": "us-east-1", "sourceIPAddress": "<ip-address>", "userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36", "requestParameters": { "networkId": 56019692 }, "responseElements": { "sessionCookie": "***", "sessionNonce": "***" }, "requestID": "39ed0e6f-36e9-460d-8a6e-f24be0ec11c5", "eventID": "98ccb633-0e6c-4325-8996-35c3043022ac", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "<account-id>", "eventCategory": "Management" }

以下範例顯示的是展示 CreateNetwork 動作的 CloudTrail 日誌項目。

{ "eventVersion": "1.08", "userIdentity": { "type": "AssumedRole", "principalId": "<principal-id>", "arn": "<arn>", "accountId": "<account-id>", "accessKeyId": "<access-key-id>", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "<principal-id>", "arn": "<arn>", "accountId": "<account-id>", "userName": "<user-name>" }, "webIdFederationData": {}, "attributes": { "creationDate": "2023-03-10T07:53:17Z", "mfaAuthenticated": "false" } } }, "eventTime": "2023-03-10T07:54:09Z", "eventSource": "wickr.amazonaws.com", "eventName": "CreateNetwork", "awsRegion": "us-east-1", "sourceIPAddress": "<ip-address>", "userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36", "requestParameters": { "networkName": "BOT_Network", "accessLevel": "3000" }, "responseElements": null, "requestID": "b83c0b6e-73ae-45b6-8c85-9910f64d33a1", "eventID": "551277bb-87e0-4e66-b2a0-3cc1eff303f3", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "<account-id>", "eventCategory": "Management" }

以下範例顯示的是展示 ListNetworks 動作的 CloudTrail 日誌項目。

{ "eventVersion": "1.08", "userIdentity": { "type": "AssumedRole", "principalId": "<principal-id>", "arn": "<arn>", "accountId": "<account-id>", "accessKeyId": "<access-key-id>", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "<principal-id>", "arn": "<arn>", "accountId": "<account-id>", "userName": "<user-name>" }, "webIdFederationData": {}, "attributes": { "creationDate": "2023-03-10T12:19:39Z", "mfaAuthenticated": "false" } } }, "eventTime": "2023-03-10T12:29:32Z", "eventSource": "wickr.amazonaws.com", "eventName": "ListNetworks", "awsRegion": "us-east-1", "sourceIPAddress": "<ip-address>", "userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36", "requestParameters": null, "responseElements": null, "requestID": "b9800ba8-541a-43d1-9c8e-efd94d5f2115", "eventID": "5fbc83d7-771b-457d-9329-f85163a6a428", "readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "<account-id>", "eventCategory": "Management" }

以下範例顯示的是展示 UpdateNetworkdetails 動作的 CloudTrail 日誌項目。

{ "eventVersion": "1.08", "userIdentity": { "type": "AssumedRole", "principalId": "<principal-id>", "arn": "<arn>", "accountId": "<account-id>", "accessKeyId": "<access-key-id>", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "<principal-id>", "arn": "<arn>", "accountId": "<account-id>", "userName": "<user-name>" }, "webIdFederationData": {}, "attributes": { "creationDate": "2023-03-08T22:42:15Z", "mfaAuthenticated": "false" } } }, "eventTime": "2023-03-08T22:42:58Z", "eventSource": "wickr.amazonaws.com", "eventName": "UpdateNetworkDetails", "awsRegion": "us-east-1", "sourceIPAddress": "<ip-address>", "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36", "requestParameters": { "networkName": "CloudTrailTest1", "networkId": <network-id> }, "responseElements": null, "requestID": "abced980-23c7-4de1-b3e3-56aaf0e1fdbb", "eventID": "a4dc3391-bdce-487d-b9b0-6f76cedbb198", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "<account-id>", "eventCategory": "Management" }

以下範例顯示的是展示 TagResource 動作的 CloudTrail 日誌項目。

{ "eventVersion": "1.08", "userIdentity": { "type": "AssumedRole", "principalId": "<principal-id>", "arn": "<arn>", "accountId": "<account-id>", "accessKeyId": "<access-key-id>", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "<principal-id>", "arn": "<arn>", "accountId": "<account-id>", "userName": "<user-name>" }, "webIdFederationData": {}, "attributes": { "creationDate": "2023-03-08T22:42:15Z", "mfaAuthenticated": "false" } } }, "eventTime": "2023-03-08T23:06:04Z", "eventSource": "wickr.amazonaws.com", "eventName": "TagResource", "awsRegion": "us-east-1", "sourceIPAddress": "<ip-address>", "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36", "requestParameters": { "resource-arn": "<arn>", "tags": { "some-existing-key-3": "value 1" } }, "responseElements": null, "requestID": "4ff210e1-f69c-4058-8ac3-633fed546983", "eventID": "26147035-8130-4841-b908-4537845fac6a", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "<account-id>", "eventCategory": "Management" }

以下範例顯示的是展示 ListTagsForResource 動作的 CloudTrail 日誌項目。

{ "eventVersion": "1.08", "userIdentity": { "type": "AssumedRole", "principalId": "<principal-id>", "arn": "<arn>", "accountId": "<account-id>", "accessKeyId": "<access-key-id>", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "<access-key-id>", "arn": "<arn>", "accountId": "<account-id>", "userName": "<user-name>" }, "webIdFederationData": {}, "attributes": { "creationDate": "2023-03-08T18:50:37Z", "mfaAuthenticated": "false" } } }, "eventTime": "2023-03-08T18:50:37Z", "eventSource": "wickr.amazonaws.com", "eventName": "ListTagsForResource", "awsRegion": "us-east-1", "sourceIPAddress": "<ip-address>", "userAgent": "axios/0.27.2", "errorCode": "AccessDenied", "requestParameters": { "resource-arn": "<arn>" }, "responseElements": { "message": "User: <arn> is not authorized to perform: wickr:ListTagsForResource on resource: <arn> with an explicit deny" }, "requestID": "c7488490-a987-4ca2-a686-b29d06db89ed", "eventID": "5699d5de-3c69-4fe8-b353-8ae62f249187", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "<account-id>", "eventCategory": "Management" }