---
name: monitoring-at_events
title: Activity tracking events for IBM Cloud Monitoring
description: IBM Cloud services, such as IBM Cloud Monitoring, generate activity tracking events.
last-updated: 2025-07-31
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/monitoring?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Activity tracking events for IBM Cloud Monitoring
{: #at_events}


IBM Cloud services, such as IBM Cloud Monitoring, generate activity tracking events.
{: shortdesc}

Activity tracking events report on activities that change the state of a service in IBM Cloud. You can use the events to investigate abnormal activity and critical actions and to comply with regulatory audit requirements.

You can use IBM Cloud Activity Tracker Event Routing, a platform service, to route auditing events in your account to destinations of your choice by configuring targets and routes that define where activity tracking events are sent. For more information, see [About IBM Cloud Activity Tracker Event Routing](https://cloud.ibm.com/docs/atracker?topic=atracker-about&format=markdown).

You can use IBM Cloud Logs to visualize and alert on events that are generated in your account and routed by IBM Cloud Activity Tracker Event Routing to an IBM Cloud Logs instance.

## Locations where activity tracking events are sent by IBM Cloud Activity Tracker Event Routing
{: #atracker-locations}



IBM Cloud Monitoring sends activity tracking events by IBM Cloud Activity Tracker Event Routing in the regions that are indicated in the following table.


| Dallas (`us-south`) | Washington (`us-east`)  | Toronto (`ca-tor`) | Montreal (`ca-mon`) | Sao Paulo (`br-sao`) |
|---------------------|-------------------------|-------------------|----------------------|----------------------|
| [Yes]{: tag-green} | [Yes]{: tag-green} | [Yes]{: tag-green} | [Yes]{: tag-green} | [Yes]{: tag-green} |
{: caption="Regions where activity tracking events are sent in Americas locations" caption-side="top"}
{: #atracker-table-1}
{: tab-title="Americas"}
{: tab-group="atracker"}
{: class="simple-tab-table"}
{: row-headers}


| Tokyo (`jp-tok`)    | Sydney (`au-syd`) |  Osaka (`jp-osa`) | Chennai (`in-che`) |
|---------------------|------------------|------------------|--------------------|
| [Yes]{: tag-green} | [Yes]{: tag-green} | [Yes]{: tag-green} | [No]{: tag-red} |
{: caption="Regions where activity tracking events are sent in Asia Pacific locations" caption-side="top"}
{: #atracker-table-2}
{: tab-title="Asia Pacific"}
{: tab-group="atracker"}
{: class="simple-tab-table"}
{: row-headers}

| Frankfurt (`eu-de`)  | London (`eu-gb`) | Madrid (`eu-es`) |
|---------------------------------------------------------------|---------------------|------------------|
| [Yes]{: tag-green} | [Yes]{: tag-green} | [Yes]{: tag-green} |
{: caption="Regions where activity tracking events are sent in Europe locations" caption-side="top"}
{: #atracker-table-3}
{: tab-title="Europe"}
{: tab-group="atracker"}
{: class="simple-tab-table"}
{: row-headers}



## Viewing activity tracking events for IBM Cloud Monitoring
{: #at-viewing}



You can use IBM Cloud Logs to visualize and alert on events that are generated in your account and routed by IBM Cloud Activity Tracker Event Routing to an IBM Cloud Logs instance.



### Launching IBM Cloud Logs from the Observability page
{: #log-launch-standalone}



For information on launching the IBM Cloud Logs UI, see [Launching the UI in the IBM Cloud Logs documentation.](https://cloud.ibm.com/docs/cloud-logs?topic=cloud-logs-instance-launch&format=markdown)


## Alerts: List of management events
{: #at_events_alerts}

| Action                                | Description                                       |
|---------------------------------------|---------------------------------------------------|
| `sysdig-monitor.alert.create`         | An event is created when you create an alert definition |
| `sysdig-monitor.alert.read`           | An event is created when you read an alert definition |
| `sysdig-monitor.alert.update`         | An event is created when you update an alert definition |
| `sysdig-monitor.alert.delete`         | An event is created when you delete an alert definition |
| `sysdig-monitor.alert.list`           | An event is created when you view the alerts in the monitoring instance  |
{: caption="Alerts: List of activity tracking actions" caption-side="top"}

## Captures: List of management events
{: #at_events_captures}


| Action                                | Description                                       |
|---------------------------------------|---------------------------------------------------|
| `sysdig-monitor.capture.create`       | An event is created when you create a Monitoring capture |
| `sysdig-monitor.capture.read`         | An event is created when you load a Monitoring capture in the dashboard |
| `sysdig-monitor.capture.update`       | An event is created when you update a Monitoring capture |
| `sysdig-monitor.capture.delete`       | An event is created when you delete a Monitoring capture |
{: caption="Captures: List of activity tracking actions" caption-side="top"}


## Dashboards: List of management events
{: #at_events_dashboards}


| Action                                | Description                                       |
|---------------------------------------|---------------------------------------------------|
| `sysdig-monitor.dashboard.create`     | An event is created when you create a dashboard |
| `sysdig-monitor.dashboard.read`       | An event is created when you load a dashboard |
| `sysdig-monitor.dashboard.update`     | An event is created when you update a dashboard |
| `sysdig-monitor.dashboard.delete`     | An event is created when you delete a dashboard |
| `sysdig-monitor.dashboard.list`       | An event is created when you view the dashboards in the monitoring instance |
{: caption="Dashboards: List of activity tracking actions" caption-side="top"}

## Teams: List of management events
{: #at_events_teams}


| Action                                | Description                                       |
|---------------------------------------|---------------------------------------------------|
| `sysdig-monitor.team.create`          | An event is created when you create a Monitoring team |
| `sysdig-monitor.team.read`            | An event is created when you view a Monitoring team definition |
| `sysdig-monitor.team.update`          | An event is created when you update a Monitoring team definition |
| `sysdig-monitor.team.delete`          | An event is created when you delete a Monitoring team |
| `sysdig-monitor.team.list`            | An event is created when you view the Monitoring teams |
{: caption="Teams: List of activity tracking actions" caption-side="top"}