---
name: cloud-logs-at_events
title: Activity tracking events for IBM Cloud Logs
description: IBM Cloud services, such as IBM Cloud Logs, generate activity tracking events.
last-updated: 2026-06-26
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/cloud-logs?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Activity tracking events for IBM Cloud Logs
{: #at_events}

IBM Cloud services, such as IBM Cloud Logs, generate activity tracking events.
{: shortdesc}

Activity tracking events report on activities that change the state of a service in IBM Cloud. You can use the events to investigate abnormal activity and critical actions and to comply with regulatory audit requirements.

You can use IBM Cloud Activity Tracker Event Routing, a platform service, to route auditing events in your account to destinations of your choice by configuring targets and routes that define where activity tracking events are sent. For more information, see [About IBM Cloud Activity Tracker Event Routing](https://cloud.ibm.com/docs/atracker?topic=atracker-about&format=markdown).

You can use IBM Cloud Logs to visualize and alert on events that are generated in your account and routed by IBM Cloud Activity Tracker Event Routing to an IBM Cloud Logs instance.

## Locations where activity tracking events are generated
{: #at-locations}

IBM Cloud Logs sends activity tracking events by IBM Cloud Activity Tracker Event Routing in the regions that are indicated in the following table.



| Dallas (`us-south`) | Washington (`us-east`)  | Toronto (`ca-tor`) |  Montreal (`ca-mon`) | Sao Paulo (`br-sao`) |
|---------------------|-------------------------|-------------------|-------------------|----------------------|
| [Yes]{: tag-green} | [Yes]{: tag-green} | [Yes]{: tag-green} | [Yes]{: tag-green} | [Yes]{: tag-green} |
{: caption="Regions where activity tracking events are sent in Americas locations" caption-side="top"}
{: #atracker-table-1}
{: tab-title="Americas"}
{: tab-group="atracker"}
{: class="simple-tab-table"}
{: row-headers}


| Tokyo (`jp-tok`)    | Sydney (`au-syd`) |  Osaka (`jp-osa`) | Chennai (`in-che`) | Mumbai (`in-mum`) |
|---------------------|------------------|------------------|--------------------|--------------------|
| [Yes]{: tag-green} | [Yes]{: tag-green} | [Yes]{: tag-green} | [Yes]{: tag-red} | [Yes]{: tag-green} |
{: caption="Regions where activity tracking events are sent in Asia Pacific locations" caption-side="top"}
{: #atracker-table-2}
{: tab-title="Asia Pacific"}
{: tab-group="atracker"}
{: class="simple-tab-table"}
{: row-headers}

| Frankfurt (`eu-de`)  | London (`eu-gb`) | Madrid (`eu-es`) |
|----------------------|------------------|------------------|
| [Yes]{: tag-green} | [Yes]{: tag-green} | [Yes]{: tag-green} |
{: caption="Regions where activity tracking events are sent in Europe locations" caption-side="top"}
{: #atracker-table-3}
{: tab-title="Europe"}
{: tab-group="atracker"}
{: class="simple-tab-table"}
{: row-headers}


## Viewing activity tracking events for IBM Cloud Logs
{: #at-viewing}


You can use IBM Cloud Logs to visualize and alert on events that are generated in your account and routed by IBM Cloud Activity Tracker Event Routing to an IBM Cloud Logs instance.

### Launching IBM Cloud Logs from the Observability page
{: #log-launch-standalone}

For information on launching the IBM Cloud Logs UI, see [Launching the UI.](https://cloud.ibm.com/docs/cloud-logs?topic=cloud-logs-instance-launch&format=markdown)


## List of platform events
{: #at_actions_platform}

The following table lists the activity tracking event actions that the IBM Cloud platform generates when IBM Cloud Logs instances are processed.

| Action                                   | Description |
|------------------------------------------|---------|
| `logs.instance.create`           | An event is generated when you provision a service instance. |
| `logs.instance.update`           | An event is generated when you rename a service instance or when you change the service plan. |
| `logs.instance.delete`           | An event is generated when a service instance is deleted. |
| `logs.instance.schedule_reclaim` | An event is generated when a service instance is pending_reclamation. |
| `logs.instance.restore`          | An event is generated when a service instance is restored. |
{: caption="Actions that generate platform events" caption-side="bottom"}

## Action events
{: #at_events_action}

The following table lists the action events that are generated by IBM Cloud Logs:

| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.action.list` |	Reading actions configuration | 
| `logs.action.update` |	Updating actions configuration |
| `logs.action.delete` |	Deleting actions configuration |
{: caption="Events for actions" caption-side="top"}

## Alert events
{: #at_events_alert}

The following table lists the alert events that are generated by IBM Cloud Logs:


| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.alert-config.list` |	Listing alerts |
| `logs.alert-config.create` |	Creating an alert |
| `logs.alert-config.update` |	Updating an alert |
| `logs.alert-config.delete` |	Deleting an alert |
| `logs.alert.snooze` |	Snoozing or unsnoozing an alert |
{: caption="Events for alert" caption-side="top"}

## Archive log events
{: #at_events_archive_log}

The following table lists the archive log events that are generated by IBM Cloud Logs:

| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.archive-setup.get` |	Run a query directly on the data bucket  |
{: caption="Events for archive logs" caption-side="top"}

## Benchmark events
{: #at_events_benchmark}

The following table lists the benchmark events that are generated by IBM Cloud Logs:

| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.version-benchmark-tags.update` |	Updating version benchmark tags |
| `logs.version-benchmark-tags.delete` |	Deleting version benchmark tags |
{: caption="Events for benchmarks" caption-side="top"}

## Data access rule events
{: #at_events_data_access_rule}

The following table lists the data access rule events that are generated by IBM Cloud Logs:

| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.data-access-rule.list` |	Listing data access rules |
| `logs.data-access-rule.create` |	Creating a data access rule |
| `logs.data-access-rule.update` |	Updating a data access rule |
| `logs.data-access-rule.delete` |	Deleting a data access rule |
{: caption="Events for data access rule" caption-side="top"}

## Data usage events
{: #at_events_data_usage}

The following table lists the data usage events that are generated by IBM Cloud Logs:

| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.data-usage.get`	| Getting data usage for each requested day |
| `logs.data-usage-to-metrics.enable`	| Enabling data usage to metrics |
| `logs.data-usage.export`	| Exporting the data usage report  |
{: caption="Events for data usage" caption-side="top"}

The `requestData.data.value` field is set to `false` when the *Enable data usage metrics* toggle is disable in the UI.
{: note}

## Dashboard events
{: #at_events_dashboard}

The following table lists the dashboard events that are generated by IBM Cloud Logs:

| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.dashboard.get` |	Getting a dashboard |
| `logs.dashboard.pin` |	Marking a dashboard as `Favorite` |
| `logs.dashboard.unpin` |	Unmarking a dashboard as `Favorite` |
| `logs.dashboard.set-as-default` |	Marking dashboard as `Default` |
| `logs.dashboard.create` |	Creating a dashboard |
| `logs.dashboard.update` |	Updating a dashboard |
| `logs.dashboard.delete` |	Deleting a dashboard |
{: caption="Events for dashboards" caption-side="top"}

## Enrichment events
{: #at_events_enrichment}

The following table lists the events that are generated by IBM Cloud Logs for enrichments:

| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.enrichment.list` |	Listing the geo or custom enrichment configurations |
| `logs.custom-enrichment.overwrite` |	Creating or updating the custom enrichment configuration |
| `logs.custom-enrichment-data.list` |	Getting all custom enrichment data |
| `logs.custom-enrichment-data.create` |	Creating a custom enrichment  |
| `logs.custom-enrichment-data.update` |	Updating a custom enrichment  |
| `logs.custom-enrichment-data.delete` |	Deleting a custom enrichment  |
| `logs.geo-enrichment.create` |	Creating a geo enrichment configuration |
| `logs.geo-enrichment.delete` |	Deleting a geo enrichment configuration |
{: caption="Events for enrichments" caption-side="top"}


## Events to Metrics events
{: #at_events_events2metrics}

The following table lists the Events to Metrics events that are generated by IBM Cloud Logs:


| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.events2metrics.list` |	Listing the events2metrics configuration |
| `logs.events2metrics.create` |	Creating the events2metrics configuration |
| `logs.events2metrics.update` |	Updating the events2metrics configuration |
| `logs.events2metrics.delete` |	Deleting the events2metrics configuration |
{: caption="Events for events2metrics" caption-side="top"}

[*] Only generated via API.
{: note}




## Extension events
{: #at_events_extension}

The following table lists the extension events that are generated by IBM Cloud Logs:

| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.extension.list` |	Getting all extensions |
| `logs.extension.get` |	Getting an extension by ID |
| `logs.extension.deploy` |	Deploying an extension |
| `logs.extension.update` |	Updating an extension |
| `logs.extension.undeploy` |	Removing/undeploying an extension |
{: caption="Events for extension data" caption-side="top"}

## Folder events
{: #at_events_folder}

The following table lists the folder events that are generated by IBM Cloud Logs:

| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.view-folder.list` |	Listing the view folders |
| `logs.view-folder.get` |	Getting the view folder |
| `logs.view-folder.create` |	Creating the view folder|
| `logs.view-folder.update` |	Updating the view folder|
| `logs.view-folder.delete` |	Deleting the view folder|
{: caption="Events for folders" caption-side="top"}

## Incident events
{: #at_events_incident}

The following table lists the incident events that are generated by IBM Cloud Logs:


| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.incident.get` |	Getting an incident |
| `logs.incident.list` |	Listing incidents |
| `logs.incident.acknowledge` |	Acknowledging an event in a triggered incident |
| `logs.incident.close`	| Closing incidents |
{: caption="Events for incidents" caption-side="top"}


## LiveTail events
{: #at_events_livetail}

The following table lists the LiveTail events that are generated by IBM Cloud Logs:

| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.livetail.search` | 	Searching LiveTail data |
{: caption="Events for LiveTail data" caption-side="top"}


## Log events
{: #at_events_log}

The following table lists the log events that are generated by IBM Cloud Logs:

| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.logs-data.search` |	Searching logs data |
{: caption="Events for logs" caption-side="top"}

## Streamming events
{: #at_events_logs_stream}

The following table lists the logs stream events that are generated by IBM Cloud Logs:

| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.logs-stream-setup.list` | Listing logs stream |
{: caption="Events for logs stream" caption-side="top"}

## Outbound Integrations events
{: #at_events_outbound_integrations}

The following table lists the outbound integrations events that are generated by IBM Cloud Logs:

| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.webhook.list` | Listing webhook outbound integrations |
| `logs.webhook.get` |	Getting webhook outbound integrations |
| `logs.webhook.create` |	Creating webhook outbound integrations |
| `logs.webhook.update` |	Updating webhook outbound integrations |
| `logs.webhook.delete` |	Deleting webhook outbound integrations |
| `logs.webhook.test` |	Testing webhook outbound integrations |
{: caption="Events for outbound integrations" caption-side="top"}

## Parsing rule events
{: #at_events_parsing_rule}

The following table lists the parsing rule events that are generated by IBM Cloud Logs:


| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.parsing-rule.get` | 	Getting rule groups |
| `logs.parsing-rule.list` | 	Listing rule groups |
| `logs.parsing-rule.create` |	Creating a rule group |
| `logs.parsing-rule.update` |	Updating a rule group |
| `logs.parsing-rule.delete` |	Deleting a rule group |
| `logs.parsing-rule.order` |	Reordering the sequence of the rule groups |
{: caption="Events for parsing rules" caption-side="top"}

## Suppression Rule events
{: #at_events_suppression_rule}

The following table lists the suppression rule events that are generated by IBM Cloud Logs:

| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.suppression-rule.list` | Listing suppression rules |
| `logs.suppression-rule.create` | Creating suppression rule |
| `logs.suppression-rule.update` | Updating suppression rule |
| `logs.suppression-rule.delete` | Deleting suppression rule |
{: caption="Events for suppression rule" caption-side="top"}

## TCO policy events
{: #at_events_tco_policy}

The following table lists the TCO policy events that are generated by IBM Cloud Logs:

| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.logs-tco-policy.get` | 	Getting a TCO policy |
| `logs.logs-tco-policy.create` |	Creating a TCO policy |
| `logs.logs-tco-policy.update` |	Updating a TCO policy |
| `logs.logs-tco-policy.list` |	Listing TCO policies |
| `logs.logs-tco-policy.delete` |	Deleting a TCO policy | 
{: caption="Events for TCO policies" caption-side="top"}


## View events
{: #at_events_view}

The following table lists the view events that are generated by IBM Cloud Logs:

| Event                                            | Description                |
|---------------------------------------------------|----------------------------|
| `logs.view.list`         |	Listing views |
| `logs.view.get` |	Viewing a views |
| `logs.view.create` |	Creating a view |
| `logs.view.update` |	Updating a view |
| `logs.view.delete` |	Deleting a view |
{: caption="Events for views" caption-side="top"}

The `requestData.newValue.isPublic` field is set to `true` for public views and `false` for private views.
{: note}