Skip to main content

Audit log events

Last update:

In audit logs, an event is a record of a creation, modification, or deletion operation on resources and entities. Reading sensitive data, such as passwords, certificates, etc., is also recorded in audit logs.

An event has a fixed structure and can be of different types.

Event structure

An event has a JSON structure:

[
{
"event_saved_time": "2025-09-29T13:13:25.196Z",
"event_id": "string",
"event_type": "string",
"event_time": "2025-09-29T13:13:25.196Z",
"status": "string",
"error_code": "string",
"request_id": "string",
"subject": {
"id": "string",
"type": "string",
"name": "string",
"auth_provider": "string",
"is_authorized": true,
"authorized_by": [
"string"
],
"credentials_fingerprint": "string"
},
"resource": {
"id": "string",
"type": "string",
"name": "string",
"account_id": "string",
"project_id": "string",
"location": "string",
"details": {},
"old_values": {
"additionalProp1": {}
},
"new_values": {
"additionalProp1": {}
}
},
"source_type": "string",
"request": {
"remote_address": "string",
"user_agent": "string",
"type": "string",
"path": "string",
"method": "string",
"parameters": "string"
},
"schema_version": "string"
}
]

Some fields are optional and may be absent in an event. Some fields also have reserved values.

Event fields

FieldDescriptionData typeRequired
event_idUnique event identifierString
event_typeEvent type; for the full list, see the Event types subsectionString
event_timeTime the event occurred in ISO8601 format with timezoneString
event_saved_timeTime the event was saved in audit logs in ISO8601 format with timezoneString
status

Event status. Possible values:

  • success;
  • fail;
  • accepted;
  • NA (not applicable) — none of the statuses apply to the event
String
error_codeError codeString
request_idUnique event chain identifier or request identifierString
subjectInformation about the subject—a service or user that performed the operationObject
id

Unique identifier of the action subject. Example formats:

  • 12345_13423;
  • 3112f9b7aec64fe49700c7cd0f5f6ddc. You can use subject_id to identify the user. If the value could not be retrieved, undefined will be specified.
String
type

Subject type. Possible values:

  • employee — Selectel employee;
  • user — user;
  • service_user — service user;
  • service — Selectel service
String
nameSubject nameString
auth_provider

Subject authentication provider. Possible values:

  • keystone — IAM token;
  • api_key — static token;
  • session — session identifier
String
is_authorizedAuthorization resultBoolean
authorized_byList of roles and other authorization attributes used to authorize the requestArray of strings
credentials_fingerprintFingerprint of the secret used to authorize the requestString
resourceAction object; the entity on which the subject performed the operation. An object can be a resource (server, disk), user, role, account, etc.Object
idUnique object identifierString
typeObject typeString
nameObject nameString
account_idAccount identifierString
project_idProject identifierString
locationData center, availability zone, or pool where the subject is locatedString
detailsEvent details. Defined by the source service and event typeObject
changesChanges that occurred to the subjectObject
changes_old_valuesSet of old subject attribute valuesObject
changes_new_valuesSet of new subject attribute valuesObject
sourceService that recorded the changeObject
typeName of the product, service, or feature where the event occurredString
requestRequest informationObject
remote_addressIP address the request came fromString
user_agentUser Agent of the event subjectString
type

Request type. Possible values:

  • http;
  • grpc;
  • queue;
  • internal
String
pathPath to the resource where the event occurredString
methodRequest methodString
parametersQuery parametersString
schema_versionFixed value — 1.0String

Reserved values

If a field value cannot be determined by the log source services — for example, if an error occurred during the action or the object has not yet been created and there is no resource_id — the reserved value undefined is used.

It can appear in the following fields:

  • subject_id;
  • subject_type;
  • resource_id;
  • resource_type;
  • resource_account_id.

Event types (event_type)

In audit logs, event types are grouped by services that are responsible for different parts of products. Using services, you can filter events when unloading logs via the Control Panel and via the Audit Logs API.

The list of products that support audit logs, services, and event types will be expanded.

Product or management areaServices
Account, users, projects, and permissionsiam
Billing, payment informationlegal
billing
Dedicated servers, Colocation, basic firewall, storage systemsdedicated
Cloud platformvpc
quota_management
compute
filestorage
Secrets managersecrets
Certificate managercertificates
Logslogs
Audit logsaudit_logs
Domainsdomains
DNS Hostingdns
Global Routerglobal_router
Managed Kubernetesmks
S3s3
Managed databasesdbaas

IAM service

Responsible for operations on the account, with users, projects, and access permissions. You can manage some of them (for example, users and their keys) through the IAM API.

Event name (event_type)Description
Accountiam.account.init_actionSubject authentication upon performing an operation in the billing service. Linked to the main operation event via the request_id field.
iam.account.email_confirmationEmail address verification during account registration
iam.account.phone_confirmationPhone number verification during account registration
iam.account.fillFilling out account details
iam.account.deleteAccount deletion
iam.account.updateUpdating account details
Account loginiam.user.loginUser login to the account
iam.user_password.checkUser password entry
iam.user.logoutUser account logout
iam.user_2fa_code.verify2FA login attempt
iam.user_session.reset_all_otherResetting all sessions except the current one
iam.user_session.reset_all_within_browserLogging out from all accounts signed in within the browser
iam.user_session.reset_allForced session termination by the system
Passwordiam.user_password.reset_requestRequesting a password reset link by email
iam.user_password.reset_applyPassword reset with creation of a new password
iam.user_password.updateChanging the password
Two-factor authenticationiam.user_2fa.enableEnabling two-factor authentication
iam.user_2fa.disableDisabling two-factor authentication
iam.user_2fa_code.sendRequesting a two-factor authentication code
iam.user_2fa_backup_codes.createCreating backup codes
iam.user_2fa_otp.enableEnabling login via an authenticator app
iam.user_2fa_email.enableEnabling login via email
iam.user_2fa_sms.enableEnabling login via SMS
iam.user_2fa_backup_codes.enableEnabling login using backup codes and creating them
iam.user_2fa_otp.disableDisabling login via an authenticator app
iam.user_2fa_email.disableDisabling login via email
iam.user_2fa_sms.disableDisabling login via SMS
Changing contact informationiam.user_email.change_initRequest to change the email address
iam.user_email.change_unlockedConfirming the email address change
iam.user_email.updateSuccessful change of the email address
iam.user_phone.change_initRequest to change the phone number
iam.user_phone.change_unlockedConfirming the phone number change
iam.user_phone.updateSuccessful change of the phone number
Usersiam.user_profile.createCreating a new user profile
iam.user.email_confirmationRegistering a new user via the link from the invitation email
iam.federated_user_profile.createCreating a federated user profile
iam.user.phone_confirmationPhone number confirmation during new user registration
iam.user_profile.fillUser filling out their own profile data
iam.user_profile.updateUser updating their own profile data
iam.federated_user_profile.updateUpdating federated user profile data
iam.user_profile.deleteDeleting a user profile
iam.federated_user_profile.deleteDeleting a federated user profile
iam.user_subscription.addAdding an notification category to a user
iam.user_subscription.deleteRemoving a notification category from a user
iam.user.createCreating a user
iam.user.deleteDeleting a user
iam.user_role.addAssigning roles to a user
iam.user_role.removeRemoving roles from a user
iam.user_group.addAssigning groups to a user
iam.user_group.removeRemoving groups from a user
Service usersiam.service_user.createCreating a service user
iam.service_user.updateUpdating a service user
iam.service_user.deleteDeleting a service user
iam.service_user_role.addAssigning roles to a service user
iam.service_user_role.removeRemoving roles from a service user
iam.service_user_group.addAssigning groups to a service user
iam.service_user_group.removeRemoving groups from a service user
User groupiam.group.createCreating a user group
iam.group.updateUpdating a user group
iam.group.deleteDeleting a user group
iam.group_user.addAdding users to a group
iam.group_user.removeRemoving users from a group
iam.group_role.addAssigning roles to a user group
iam.group_role.removeRemoving roles from a user group
Federationsiam.federation.createCreating a federation
iam.federation.updateUpdating a federation
iam.federation.deleteDeleting a federation
iam.federation_cert.createCreating a federation certificate
iam.federation_cert.updateUpdating a federation certificate
iam.federation_cert.deleteDeleting a federation certificate
iam.federation_group_mapping.createCreating a mapping for a Selectel user group to an identity provider group
iam.federation_group_mapping.updateReplacing all user group mappings for a federation with mappings to other identity provider groups
iam.federation_group_mapping.deleteRemoving a mapping for a Selectel user group to an identity provider group
Projectsiam.project.createCreating a project
iam.project.updateUpdating a project
iam.project_domain.detachRemoving a project domain
iam.project.deleteDeleting a project
IAM tokensiam.auth_token.issueIssuing an IAM token
iam.auth_token.revokeRevoking an IAM token
S3 keysiam.user_credential.addCreating an S3 key for a user
iam.user_credential.removeRemoving an S3 key from a user
iam.service_user_credential.addCreating an S3 key for a service user
iam.service_user_credential.removeRemoving an S3 key from a service user
Static tokensiam.api_key.createCreating a static token
iam.api_key.updateUpdating a static token
iam.api_key.enableActivating a static token
iam.api_key.disableDeactivating a static token
iam.api_key.deleteDeleting a static token
ACLiam.acl.enableEnabling ACL
iam.acl.disableDisabling ACL
iam.acl_ip.createCreating an ACL rule
iam.acl_ip.deleteRemoving an ACL rule

Responsible for operations with the customer of the contract — the payer.

Event name (event_type)Description
Contract customerlegal.payer.createCreating a customer
legal.payer.updateUpdating customer data
legal.payer.reorganisationReorganizing a customer company

Billing service

Responsible for operations that occur with resources in case of deferred payment, non-payment, or debt repayment.

In billing service events, detailed information about the subject is provided in the paired authentication event. In it, events with the iam.account.init_action type are merged with the main event via the request_id field.

Event name (event_type)Description
Cloud platform financial signalsbilling.block_signal.applyResource blocking
billing.unblock_signal.applyResource unblocking
billing.restrict_signal.applyRestricting access to a resource
billing.unrestrict_signal.applyRemoving access restrictions from a resource
billing.delete_signal.applyDeleting a resource
Deferred paymentbilling.soft_grace_policy.enableEnabling deferred payment
billing.soft_grace_policy.disableDisabling deferred payment
billing.soft_grace_signal.applyActivating deferred payment
billing.unsoft_grace_signal.applyCompleting an active deferred payment

Dedicated service

Responsible for operations:

You can manage servers and equipment through the Dedicated Servers API.

Event name (event_type)Description
Dedicated serverdedicated.server.createOrdering a dedicated server
dedicated.server.updateModifying a dedicated server
dedicated.server.deleteDeleting a dedicated server
dedicated.server.power_onPowering on a dedicated server
dedicated.server.power_offPowering off a dedicated server
dedicated.server.rebootRebooting a dedicated server
dedicated.server.os_reinstallReinstalling the OS on a dedicated server
dedicated.server.password_showViewing the password for a dedicated server
dedicated.server.console_openOpening the console of a dedicated server
dedicated.server.upgrade_createCreating a server upgrade
dedicated.server.upgrade_cancelCanceling a server upgrade
Additional servicesdedicated.additional_resource.createOrdering an additional service
dedicated.additional_resource.updateModifying an additional service
dedicated.additional_resource.deleteDeleting an additional service
Colocationdedicated.colocation.createOrdering Colocation
dedicated.colocation.updateModifying Colocation
dedicated.colocation.deleteDeleting Colocation
Firewalldedicated.firewall.createOrdering a firewall
dedicated.firewall.updateModifying a firewall
dedicated.firewall.deleteDeleting a firewall
Network equipmentdedicated.network_equipment.createOrdering network equipment
dedicated.network_equipment.updateModifying network equipment
dedicated.network_equipment.deleteDeleting network equipment
Equipment
(data storage systems)
dedicated.equipment.createOrdering equipment
dedicated.equipment.updateModifying equipment
dedicated.equipment.deleteDeleting equipment
Network servicededicated.network.createOrdering a network service
dedicated.network.updateModifying a network service
dedicated.network.deleteDeleting a network service
Port servicededicated.port.createOrdering a port service
dedicated.port.updateModifying a port service
dedicated.port.deleteDeleting a network service
Softwarededicated.software.createOrdering software
dedicated.software.updateModifying software
dedicated.software.deleteDeleting software
Tagsdedicated.tag.createOrdering software
dedicated.tag.updateModifying software
dedicated.tag.deleteDeleting software
Basic firewalldedicated.basic_firewall.createCreating a basic firewall
dedicated.basic_firewall.updateModifying a basic firewall
dedicated.basic_firewall.deleteDeleting a basic firewall
Public subnetworkdedicated.public_subnet.createCreating a public subnetwork
dedicated.public_subnet.updateModifying a public subnetwork
dedicated.public_subnet.deleteDeleting a public subnetwork
Private subnetworkdedicated.private_subnet.createCreating a private subnetwork
dedicated.private_subnet.updateModifying a private subnetwork
dedicated.private_subnet.deleteDeleting a private subnetwork
Public VLANdedicated.public_vlan.createCreating a public VLAN
dedicated.public_vlan.updateModifying a public VLAN
dedicated.public_vlan.deleteDeleting a public VLAN
Private VLANdedicated.private_vlan.createCreating a private VLAN
dedicated.private_vlan.updateModifying a private VLAN
dedicated.private_vlan.deleteDeleting a private VLAN
SSH keysdedicated.ssh_key.createCreating an SSH key
dedicated.ssh_key.updateModifying an SSH key
dedicated.ssh_key.deleteDeleting an SSH key

VPC service

Handles operations with cloud platform networks, cloud firewalls, private DNS, security groups, cloud load balancers.

Event name (event_type)Description
Private networksvpc.network.create

cloud_network.network.create *
Creating a private network
vpc.network.update

cloud_network.network.update *
Modifying a private network
vpc.network.delete

cloud_network.network.delete *
Deleting a private network
Private subnetworksvpc.subnet.create

cloud_network.subnet.create *
Creating a private subnetwork
vpc.subnet.update

cloud_network.subnet.update *
Modifying a private subnetwork
vpc.subnet.delete

cloud_network.subnet.delete *
Deleting a private subnetwork
Public subnetworksvpc.subnet.create

cloud_network.subnet.create *
Creating a public subnetwork
vpc.subnet.bulk_create

cloud_network.subnet.bulk_create *
Adding a public subnetwork to a project
vpc.subnet.update

cloud_network.subnet.update *
Modifying a public subnetwork
vpc.subnet.delete

cloud_network.subnet.delete *
Deleting a public subnetwork
vpc.subnet.init_delete

cloud_network.subnet.init_delete *
Deleting a public subnetwork from a project
Subnetwork poolsvpc.subnet_pool.create

cloud_network.subnetpool.create *
Creating a subnetwork pool
vpc.subnet_pool.update

cloud_network.subnetpool.update *
Modifying a subnetwork pool
vpc.subnet_pool.delete

cloud_network.subnetpool.delete *
Deleting a subnetwork pool
Address scopesvpc.address_scope.create

cloud_network.address_scope.create *
Creating an address scope
vpc.address_scope.update

cloud_network.address_scope.update *
Modifying an address scope
vpc.address_scope.delete

cloud_network.address_scope.delete *
Deleting an address scope
Address groupsvpc.address_group.create

cloud_network.address_group.create *
Creating an address group
vpc.address_group.update

cloud_network.address_group.update *
Modifying an address group
vpc.address_group.delete

cloud_network.address_group.delete *
Deleting an address group
Public IP addressesvpc.floatingip.create

cloud_network.floatingip.create *
Creating a public IP address
vpc.floatingip.bulk_create

cloud_network.floatingip.bulk_create *
Adding a public IP address to a project
vpc.floatingip.update

cloud_network.floatingip.update *
Modifying a public IP address, including connecting to or disconnecting from a port
vpc.floatingip_port_forwarding.create

cloud_network.port_forwarding.create *
Creating port forwarding (1:1 NAT via a cloud router)
vpc.floatingip_port_forwarding.update

cloud_network.port_forwarding.update *
Modifying port forwarding (1:1 NAT via a cloud router)
vpc.floatingip_port_forwarding.delete

cloud_network.port_forwarding.delete *
Deleting port forwarding (1:1 NAT via a cloud router)
vpc.floatingip.init_delete

cloud_network.floatingip.init_delete *
Deleting a public IP address from a project
vpc.floatingip.delete

cloud_network.floatingip.delete *
Deleting a public IP address
Portsvpc.port.create

cloud_network.port.create *
Creating a port
vpc.port.update

cloud_network.port.update *
Modifying a port
vpc.port.delete

cloud_network.port.delete *
Deleting a port
Cloud routersvpc.router.create

cloud_network.router.create *
Creating a cloud router
vpc.router.update

cloud_network.router.update *
Modifying a cloud router
vpc.router.delete

cloud_network.router.delete *
Deleting a cloud router
vpc.router.add_interface

cloud_network.router.add_router_interface *
Connecting a subnetwork to a router
vpc.router.remove_interfaces

cloud_network.router.remove_router_interface *
Disconnecting a subnetwork from a router
Security groupsvpc.security_group.create

cloud_network.security_group.create *
Creating a security group
vpc.security_group.update

cloud_network.security_group.update *
Modifying a security group
vpc.security_group.delete

cloud_network.security_group.delete *
Deleting a security group
vpc.security_group_rule.create

cloud_network.security_group_rule.create *
Creating a security group rule
vpc.security_group_rule.delete

cloud_network.security_group_rule.delete *
Deleting a security group rule
Resource access policiesvpc.rbac_policy.create

cloud_network.rbac_policy.create *
Creating an access policy
vpc.rbac_policy.update

cloud_network.rbac_policy.update *
Modifying an access policy
vpc.rbac_policy.delete

cloud_network.rbac_policy.delete *
Deleting an access policy
Cloud firewallsvpc.firewall.create

cloud_network.firewall.create *
Creating a firewall
vpc.firewall.update

cloud_network.firewall.update *
Modifying a firewall
vpc.firewall.delete

cloud_network.firewall.delete *
Deleting a firewall
vpc.firewall_rule.create

cloud_network.firewall_rule.create *
Creating a firewall rule
vpc.firewall_rule.update

cloud_network.firewall_rule.update *
Modifying a firewall rule
vpc.firewall_rule.delete

cloud_network.firewall_rule.delete *
Deleting a firewall rule
vpc.firewall_policy.create

cloud_network.firewall_policy.create *
Creating a firewall policy
vpc.firewall_policy.update

cloud_network.firewall_policy.update *
Modifying a firewall policy
vpc.firewall_policy.delete

cloud_network.firewall_policy.delete *
Deleting a firewall policy
Private DNSvpc.private_dns_zone.createCreating a zone
vpc.private_dns_zone.updateUpdating a zone
vpc.private_dns_zone.deleteDeleting a zone
vpc.private_dns_zone.update_recordsetModifying zone records
vpc.private_dns_service.createConnecting a network to a private DNS resolver
vpc.private_dns_service.deleteDisconnecting a network from a private DNS resolver
vpc.private_dns_service.updateModifying network connection settings for a private DNS resolver
vpc.private_dns_service.update_networkReconfiguring private DNS resolver ports
Load balancervpc.load_balancer.create

cloud_load_balancer.load_balancer.create *
Creating a load balancer
vpc.load_balancer.update

cloud_load_balancer.load_balancer.update *
Modifying a load balancer
vpc.load_balancer.delete

cloud_load_balancer.load_balancer.delete *
Deleting a load balancer
vpc.load_balancer.failover

cloud_load_balancer.load_balancer.failover *
Triggering load balancer recreation
vpc.load_balancer_log_offloading.enable

cloud_load_balancer.load_balancer_log_offloading.update *
Enabling a load balancer log offloading task
vpc.load_balancer_log_offloading.disable

cloud_load_balancer.load_balancer_log_offloading.delete *
Disabling a load balancer log offloading task
vpc.load_balancer_pool_member.create

cloud_load_balancer.member.create *
Adding a server to a load balancer target group
vpc.load_balancer_pool_member.update

cloud_load_balancer.member.update *
Modifying a server in a load balancer target group
vpc.load_balancer_pool_member.delete

cloud_load_balancer.member.delete *
Deleting a server from a load balancer target group
vpc.load_balancer_pool.create

cloud_load_balancer.pool.create *
Creating a load balancer target group
vpc.load_balancer_pool.update

cloud_load_balancer.pool.update *
Modifying a load balancer target group
vpc.load_balancer_pool.delete

cloud_load_balancer.pool.delete *
Deleting a load balancer target group
vpc.load_balancer_listener.create

cloud_load_balancer.listener.create *
Creating a load balancer rule
vpc.load_balancer_listener.update

cloud_load_balancer.listener.update *
Modifying a load balancer rule
vpc.load_balancer_listener.delete

cloud_load_balancer.listener.delete *
Deleting a load balancer rule
vpc.load_balancer_l7_policy.create

cloud_load_balancer.l7_policy.create *
Creating a load balancer HTTP policy
vpc.load_balancer_l7_policy.update

cloud_load_balancer.l7_policy.update *
Modifying a load balancer HTTP policy
vpc.load_balancer_l7_policy.delete

cloud_load_balancer.l7_policy.delete *
Deleting a load balancer HTTP policy
vpc.load_balancer_l7_policy_rule.create

cloud_load_balancer.rule.create *
Creating a load balancer L7 rule
vpc.load_balancer_l7_policy_rule.update

cloud_load_balancer.rule.update *
Modifying a load balancer L7 rule
vpc.load_balancer_l7_policy_rule.delete

cloud_load_balancer.rule.delete *
Deleting a load balancer L7 rule
vpc.load_balancer_healthmonitor.create

cloud_load_balancer.healthmonitor.create *
Creating a load balancer health check
vpc.load_balancer_healthmonitor.update

cloud_load_balancer.healthmonitor.update *
Modifying a load balancer health check
vpc.load_balancer_healthmonitor.delete

cloud_load_balancer.healthmonitor.delete *
Deleting a load balancer health check
vpc.load_balancer_amphorae.delete

cloud_load_balancer.amphorae.delete *
Deleting a load balancer instance
vpc.load_balancer_amphorae.failover

cloud_load_balancer.amphorae.failover *
Triggering load balancer instance recreation

* This event is obsolete and will soon cease to be recorded in audit logs.

quota_manager service

Handles operations with project quotas. You can manage quotas via Quota Management API.

Event name (event_type)Description
Quotasquota_manager.project.updateUpdating quotas

compute service

Handles operations with licenses, cloud servers, network volumes, volume snapshots, network volume backups and cloud server images.

You can manage licenses via Cloud Platform Projects and Resources API.

Event name (event_type)Description
SSH keys (keypairs)compute.keypair.bulk_create

cloud_compute.keypair.bulk_create *
Creating a key pair (bulk operation)
compute.keypair.bulk_delete

cloud_compute.keypair.bulk_delete *
Deleting a key pair (bulk operation)
compute.keypair.create

cloud_compute.keypair.create *
Creating or importing a key pair
compute.keypair.delete

cloud_compute.keypair.delete *
Deleting a key pair
Licensescompute.license.license.bulk_create

cloud_license.license.bulk_create *
Creating a license (bulk operation)
compute.license.license.delete

cloud_license.license.delete *
Deleting a license
Cloud serverscompute.server.init_delete

cloud_compute.server.init_delete *
Initializing cloud server deletion
compute.server.init_rebuild

cloud_compute.server.init_rebuild *
Initializing cloud server recreation
compute.server.create

cloud_compute.server.create *
Creating a cloud server
compute.server.update

cloud_compute.server.update *
Updating cloud server information
compute.server.delete

cloud_compute.server.delete *
Deleting a cloud server (soft mode)
compute.server.add_floatingip

cloud_compute.server.add_floatingip *
Adding a public IP address to a cloud server
compute.server.remove_floatingip

cloud_compute.server.remove_floatingip *
Removing a public IP address from a cloud server
compute.server.add_fixedip

cloud_compute.server.add_fixedip *
Adding a fixed IP address to a cloud server
compute.server.remove_fixedip

cloud_compute.server.remove_fixedip *
Removing a fixed IP address from a cloud server
compute.server.add_security_group

cloud_compute.server.add_security_group *
Adding a security group to a cloud server
compute.server.remove_security_group

cloud_compute.server.remove_security_group *
Removing a security group from a cloud server
compute.server.set_admin_password

cloud_compute.server.set_admin_password *
Changing the cloud server OS admin password
compute.server.resize

cloud_compute.server.resize *
Initiating cloud server reconfiguration
compute.server.confirm_resize

cloud_compute.server.confirm_resize *
Confirming cloud server reconfiguration
compute.server.revert_resize

cloud_compute.server.revert_resize *
Canceling cloud server reconfiguration
compute.server.create_backup

cloud_compute.server.create_backup *
Creating a cloud server backup
compute.server.create_image

cloud_compute.server.create_image *
Creating a cloud server disk image
compute.server.lock

cloud_compute.server.lock *
Locking a cloud server
compute.server.unlock

cloud_compute.server.unlock *
Unlocking a cloud server
compute.server.pause

cloud_compute.server.pause *
Pausing a cloud server
compute.server.unpause

cloud_compute.server.unpause *
Unpausing a cloud server
compute.server.reboot

cloud_compute.server.reboot *
Rebooting a cloud server
compute.server.rebuild

cloud_compute.server.rebuild *
Recreating a cloud server
compute.server.rescue

cloud_compute.server.rescue *
Starting Rescue mode for a cloud server
compute.server.unrescue

cloud_compute.server.unrescue *
Exiting Rescue mode for a cloud server
compute.server.start

cloud_compute.server.start *
Starting a cloud server
compute.server.stop

cloud_compute.server.stop *
Shutting down a cloud server
compute.server.get_console_output

cloud_compute.server.get_console_output *
Requesting cloud server console output
compute.server.shelve

cloud_compute.server.shelve *
Shelving a cloud server
compute.server.unshelve

cloud_compute.server.unshelve *
Unshelving a cloud server
compute.server.trigger_crash_dump

cloud_compute.server.trigger_crash_dump *
Triggering a cloud server crash dump
compute.server.create_serial_console

cloud_compute.server.create_serial_console *
Creating a cloud server serial console
compute.server.create_spice_console

cloud_compute.server.create_spice_console *
Creating a cloud server SPICE console
compute.server.create_vnc_console

cloud_compute.server.create_vnc_console *
Creating a cloud server VNC console
compute.server.create_rdp_console

cloud_compute.server.create_rdp_console *
Creating a cloud server RDP console
compute.server.create_console

cloud_compute.server.create_console *
Creating a cloud server console
compute.server.create_metadata

cloud_compute.server.create_metadata *
Creating cloud server metadata
compute.server.update_metadata

cloud_compute.server.update_metadata *
Updating cloud server metadata
compute.server.update_metadata_item

cloud_compute.server.update_metadata_item *
Updating a cloud server metadata property
compute.server.delete_metadata_item

cloud_compute.server.delete_metadata_item *
Deleting a cloud server metadata property
compute.server.attach_interface

cloud_compute.server.attach_interface *
Creating an interface and connecting it to a cloud server
compute.server.detach_interface

cloud_compute.server.detach_interface *
Disconnecting an interface from a cloud server
compute.server.clear_admin_password

cloud_compute.server.clear_admin_password *
Resetting the OS admin password from the metadata server
compute.server.attach_volume

cloud_compute.server.attach_volume *
Connecting a network volume to a cloud server
compute.server.detach_volume

cloud_compute.server.detach_volume *
Disconnecting a network volume from a cloud server
compute.server.update_volume_attachment

cloud_compute.server.update_volume_attachment *
Updating information about a volume attachment to a cloud server
compute.server.replace_all_tags

cloud_compute.server.replace_all_tags *
Replacing a cloud server tag set
compute.server.add_tag

cloud_compute.server.add_tag *
Adding a tag to a cloud server
compute.server.delete_all_tags

cloud_compute.server.delete_all_tags *
Deleting all cloud server tags
compute.server.delete_tag

cloud_compute.server.delete_tag *
Deleting a cloud server tag
compute.server.leave_server_group

cloud_compute.server.leave_server_group *
Removing a cloud server from a placement group
Flavorscompute.flavor.create

cloud_compute.flavor.create *
Creating a flavor
compute.flavor.delete

cloud_compute.flavor.delete *
Deleting a flavor
Placement groupscompute.server_group.create

cloud_compute.server_group.create *
Creating a placement group
compute.server_group.delete

cloud_compute.server_group.delete *
Deleting a placement group
Public IP addressescompute.floatingip.create

cloud_compute.floatingip.create *
Creating a public IP address
compute.floatingip.delete

cloud_compute.floatingip.delete *
Deleting a public IP address
Network volumescompute.volume_attachment.create

cloud_blockstorage.volume_attachment.create *
Creating a volume attachment to a cloud server
compute.volume_attachment.delete

cloud_blockstorage.volume_attachment.delete *
Deleting a volume attachment to a cloud server
compute.volume_attachment.update

cloud_blockstorage.volume_attachment.update *
Updating a volume attachment to a cloud server
compute.volume_attachment.complete

cloud_blockstorage.volume_attachment.complete *
Marking a volume attachment to a cloud server as ready
compute.volume_metadata.create

cloud_blockstorage.volume_metadata.create *
Creating volume metadata
compute.volume_metadata.delete

cloud_blockstorage.volume_metadata.delete *
Deleting volume metadata
compute.volume_metadata.update_key

cloud_blockstorage.volume_metadata.update_key *
Updating volume metadata by key
compute.volume_metadata.update

cloud_blockstorage.volume_metadata.update *
Updating volume metadata
compute.volume.revert

cloud_blockstorage.volume.revert *
Reverting a volume to a snapshot
compute.volume_transfer.create

cloud_blockstorage.volume_transfer.create *
Creating a volume transfer to another project
compute.volume_transfer.delete

cloud_blockstorage.volume_transfer.delete *
Deleting a volume transfer to another project
compute.volume_transfer.update

cloud_blockstorage.volume_transfer.update *
Confirming a volume transfer to another project
compute.volume.create_image

cloud_blockstorage.volume.create_image *
Creating an image from a volume
compute.volume.create

cloud_compute.volume.create *

cloud_blockstorage.volume.create *
Creating a volume
compute.volume.delete

cloud_compute.volume.delete *

cloud_blockstorage.volume.delete *
Deleting a volume
compute.volume.read_image_metadata

cloud_blockstorage.volume.read_image_metadata *
Reading image metadata for a volume
compute.volume.update

cloud_blockstorage.volume.update *
Modifying volume attributes (e.g., renaming)
compute.volume.attach

cloud_blockstorage.volume.attach *
Connecting a volume to a virtual machine
compute.volume.detach

cloud_blockstorage.volume.detach *
Disconnecting a volume from a virtual machine
compute.volume.extend

cloud_blockstorage.volume.extend *
Expanding a volume
compute.volume.reimage

cloud_blockstorage.volume.reimage *
Recreating a volume from an image
compute.volume.detach_abort

cloud_blockstorage.volume.detach_abort *
Changing the volume status to IN-USE
compute.volume.detach_init

cloud_blockstorage.volume.detach_init *
Changing the volume status to DETACHING
compute.volume.attach_init

cloud_blockstorage.volume.attach_init *
Initializing a volume attachment to a cloud server
compute.volume.reserve

cloud_blockstorage.volume.reserve *
Reserving a volume for attachment to a cloud server
compute.volume.unreserve

cloud_blockstorage.volume.unreserve *
Releasing a volume reserved for attachment to a cloud server
compute.volume.update_readonly_mark

cloud_blockstorage.volume.update_readonly_mark *
Switching a volume to or from read-only mode
compute.volume.update_bootable_mark

cloud_blockstorage.volume.update_bootable_mark *
Changing the bootable flag for a volume
compute.volume.update_image_metadata

cloud_blockstorage.volume.update_image_metadata *
Adding image metadata to a volume
compute.volume.attach_terminate

cloud_blockstorage.volume.attach_terminate *
Forcibly disconnecting a network volume from a cloud server
compute.volume.delete_image_metadata

cloud_blockstorage.volume.delete_image_metadata *
Deleting image metadata from a volume by key
Snapshotscompute.snapshot.create

cloud_compute.snapshot.create *

cloud_blockstorage.snapshot.create *
Creating a volume snapshot
compute.snapshot.delete

cloud_compute.snapshot.delete *

cloud_blockstorage.snapshot.delete *
Deleting a volume snapshot
compute.snapshot.update

cloud_blockstorage.snapshot.update *
Modifying snapshot parameters (renaming)
compute.snapshot.update_status

cloud_blockstorage.snapshot.update_status *
Updating snapshot status
compute.snapshot_metadata.delete

cloud_blockstorage.snapshot_metadata.delete *
Deleting snapshot metadata
compute.snapshot_metadata.update_key

cloud_blockstorage.snapshot_metadata.update_key *
Updating snapshot metadata by key
compute.snapshot_metadata.create

cloud_blockstorage.snapshot_metadata.create *
Creating snapshot metadata
compute.snapshot_metadata.update

cloud_blockstorage.snapshot_metadata.update *
Updating snapshot metadata
Backupscompute.backup.create

cloud_blockstorage.backup.create *
Creating a backup
compute.backup.create_ondemand

cloud_blockstorage.backup.create_ondemand *
Creating an on-demand backup (on_demand)
compute.backup.delete

cloud_blockstorage.backup.delete *
Deleting a backup
compute.backup.restore

cloud_blockstorage.backup.restore *
Restoring from backup
compute.backup.update

cloud_blockstorage.backup.update *
Updating a backup
Imagescompute.image.create_metadata

cloud_compute.image.create_metadata *
Creating image metadata
compute.image.update_metadata

cloud_compute.image.update_metadata *
Updating image metadata
compute.image.update_metadata_item

cloud_compute.image.update_metadata_item *
Updating an image metadata property
compute.image.delete_metadata_item

cloud_compute.image.delete_metadata_item *
Deleting an image metadata property
compute.image.create

cloud_blockstorage.image.create *
Creating an image
compute.image.delete

cloud_compute.image.delete *

cloud_blockstorage.image.delete *
Deleting an image
compute.image.update

cloud_blockstorage.image.update *
Updating an image
compute.image.upload

cloud_blockstorage.image.upload *
Uploading an image from a file
compute.image.deactivate

cloud_blockstorage.image.deactivate *
Deactivating an image
compute.image.reactivate

cloud_blockstorage.image.reactivate *
Reactivating an image
compute.image.import

cloud_blockstorage.image.import *
Downloading an image (e.g., via a link)
compute.image_member.create

cloud_blockstorage.image_member.create *
Requesting access to an image for another project
compute.image_member.delete

cloud_blockstorage.image_member.delete *
Removing access to an image for another project
compute.image_member.update

cloud_blockstorage.image_member.update *
Updating image access status from another project
compute.image_tag.create

cloud_blockstorage.image_tag.create *
Creating an image tag
compute.image_tag.delete

cloud_blockstorage.image_tag.delete *
Deleting an image tag
compute.image.validate_url

cloud_blockstorage.image.validate_url *
Validating an image before downloading via a link
compute.image.validate_file

cloud_blockstorage.image.validate_file *
Validating an image before uploading from a file
Security groupscompute.security_group.create

cloud_compute.security_group.create *
Creating a security group
compute.security_group.update

cloud_compute.security_group.update *
Updating a security group
compute.security_group.delete

cloud_compute.security_group.delete *
Deleting a security group
compute.security_group_rule.create

cloud_compute.security_group_rule.create *
Creating a rule in a security group
compute.security_group_rule.delete

cloud_compute.security_group_rule.delete *
Deleting a rule in a security group

* This event is deprecated and will soon no longer be written to audit logs.

Filestorage service

Responsible for operations with File Storage.

Event name (event_type)Description
File Storagefilestorage.access_rule_metadata.update

cloud_filestorage.access_rule_metadata.update *
Changing File Storage access rule metadata
filestorage.access_rule_metadata.delete

cloud_filestorage.access_rule_metadata.delete *
Deleting File Storage access rule metadata
filestorage.share_network.create

cloud_filestorage.share_network.create *
Creating a network connection for File Storage
filestorage.share_network.delete

cloud_filestorage.share_network.delete *
Deleting a network for File Storage
filestorage.share_network.update

cloud_filestorage.share_network.update *
Changing a network for File Storage
filestorage.share_network_subnet.create

cloud_filestorage.share_network_subnet.create *
Creating a subnet for File Storage
filestorage.share_network_subnet.delete

cloud_filestorage.share_network_subnet.delete *
Deleting a subnet for File Storage
filestorage.metadata.create

cloud_filestorage.metadata.create *
Adding File Storage metadata
filestorage.metadata.update

cloud_filestorage.metadata.update *
Changing File Storage metadata
filestorage.metadata.delete

cloud_filestorage.metadata.delete *
Deleting a File Storage metadata attribute
filestorage.share.allow

cloud_filestorage.share.allow *
Adding an access rule for File Storage
filestorage.share.deny

cloud_filestorage.share.deny *
Deleting an access rule for File Storage
filestorage.share.create

cloud_filestorage.share.create *
Creating File Storage
filestorage.share.delete

cloud_filestorage.share.delete *
Deleting File Storage
filestorage.share.update

cloud_filestorage.share.update *
Changing File Storage attributes (e.g., renaming)
filestorage.share.extend

cloud_filestorage.share.extend *
Increasing File Storage capacity
filestorage.share.reload_network

cloud_filestorage.share.reload_network *
Updating File Storage network settings
filestorage.message.delete

cloud_filestorage.message.delete *
Deleting a message

* This event is deprecated and will soon no longer be written to audit logs.

Secrets service

Responsible for secrets in Secrets Manager. You can manage secrets via the Secrets API.

Event name (event_type)Description
Secretssecrets.secret.createCreating a secret
secrets.secret.updateUpdating a secret description
secrets.secret.getGetting a secret
secrets.secret.deleteDeleting all secrets in a project
secrets.secret.deleteDeleting a secret
Secret versionssecrets.secret_version.getGetting a secret version value
secrets.secret_version.createCreating a new secret version
secrets.secret_version.activateSetting a version as current

Certificates service

Responsible for certificates in Certificates Manager. You can manage user certificates via User Certificates API, and Let’s Encrypt® certificates via Let’s Encrypt® Certificates API.

Event name (event_type)Description
Certificatescertificates.certificate.uploadUploading a certificate
certificates.certificate.p12.getGetting a key pair
certificates.certificate.private_key.getGetting a private key
certificates.certificate.ca_chain.getGetting a CA bundle certificate chain
certificates.certificate.deleteDeleting a certificate
certificates.certificate_name.updateUpdating a certificate
certificates.le_certificate.issueIssuing a Let’s Encrypt® certificate
certificates.le_certificate.deleteDeleting a Let’s Encrypt® certificate

Logs service

Responsible for operations in Logs.

Event name (event_type)Description
Logslogs.group.createCreating a log group
logs.group.deleteDeleting a log group
logs.stream.createCreating an event stream
logs.stream.deleteDeleting an event stream

Audit logs service

Responsible for operations with audit logs.

Event name (event_type)Description
Audit logsaudit_logs.log.download

audit_logs.audit_logs.download *
Exporting audit logs

* This event is deprecated and will soon no longer be written to audit logs.

Domains service

Responsible for operations with domains.

Event name (event_type)Description
Domaindomains.domain.createCreating a domain
domains.domain.updateUpdating a domain (e.g., project, hosts, contacts)
domains.domain.deleteDeleting a domain
domains.domain.autoextendAutomatic registration renewal
domains.domain_authinfo.createGenerating a new authorization code (authInfo)
domains.domain.extendRenewing a domain for a year
domains.domain_transfer.requestInitiating a domain transfer from another registrar
domains.domain_transfer.approveConfirming a domain transfer to Selectel
domains.contact_change.requestRequesting a domain owner change (within Selectel)
domains.contact_change.approveConfirming a domain owner change
domains.contact_change.cancelCanceling a domain owner change request
domains.domain_hosts.updateUpdating a list of domain DNS hosts
Domain administratordomains.contact.createCreating a new contact person
domains.contact.updateUpdating contact information (email, phone)
domains.contact.admin_updateUpdating a contact via technical support
domains.contact.deleteDeleting a contact person

DNS service

Responsible for operations with DNS Hosting.

Event name (event_type)Description
Domain zonedns.zone.createCreating a domain zone
dns.zone.updateChanging a domain zone
dns.zone.deleteDeleting a domain zone
dns.zone_owner.updateChanging a project for a domain zone
dns.zone.protectionEnabling or disabling domain zone deletion protection
dns.zone.activationActivating a domain zone
Resource record setdns.rrset.createCreating a resource record set
dns.rrset.updateChanging a resource record set
dns.rrset.deleteDeleting a resource record set
dns.rrset.managedAdministering a resource record set by an external service

Global Router service

Responsible for operations with Global Router.

Event name (event_type)Description
Global Routerglobal_router.router.createCreating a router
global_router.router.updateChanging a router
global_router.router.delete_initInitializing router deletion
global_router.router.deleteDeleting a router
global_router.network.createCreating a Global Router network
global_router.network.updateChanging a Global Router network
global_router.network.delete_initInitializing Global Router network deletion
global_router.network.deleteDeleting a Global Router network
global_router.subnet.createCreating a Global Router subnet
global_router.subnet.updateChanging a Global Router subnet
global_router.subnet.delete_initInitializing Global Router subnet deletion
global_router.subnet.deleteDeleting a Global Router subnet
global_router.static_route.createCreating a Global Router route
global_router.static_route.updateChanging a Global Router route
global_router.static_route.delete_initInitializing Global Router route deletion
global_router.static_route.deleteDeleting a Global Router route

MKS service

Responsible for operations with clusters, node groups, and nodes in Managed Kubernetes.

Event name (event_type)Description
Clustermks.cluster.init_createCreating a cluster (event start)
mks.cluster.createCreating a cluster (event end)
mks.cluster.init_deleteDeleting a cluster (event start)
mks.cluster.deleteDeleting a cluster (event end)
mks.cluster.init_updateUpdating a cluster (event start)
mks.cluster.updateUpdating a cluster (event end)
mks.cluster.init_upgrade_minorUpdating cluster minor version (event start)
mks.cluster.upgrade_minorUpdating cluster minor version (event end)
mks.cluster.init_upgrade_patchUpdating cluster patch version (event start)
mks.cluster.upgrade_patchUpdating cluster patch version (event end)
mks.cluster_certs.init_rotateRotating cluster certificates (event start)
mks.cluster_certs.rotateRotating cluster certificates (event end)
Node groupmks.cluster_nodegroup.init_createCreating a node group (event start)
mks.cluster_nodegroup.createCreating a node group (event end)
mks.cluster_nodegroup.init_deleteDeleting a node group (event start)
mks.cluster_nodegroup.deleteDeleting a node group (event end)
mks.cluster_nodegroup.init_updateUpdating a node group (event start)
mks.cluster_nodegroup.updateUpdating a node group (event end)
mks.cluster_nodegroup.init_resizeResizing a node group (event start)
mks.cluster_nodegroup.resizeResizing a node group (event end)
mks.cluster_nodegroup.update_autoscaleChanging Autoscaler parameters for a node group
Nodemks.cluster_nodegroup_node.init_deleteDeleting a node (event start)
mks.cluster_nodegroup_node.deleteDeleting a node (event end)
mks.cluster_nodegroup_node.init_reinstallReinstalling a node (event start)
mks.cluster_nodegroup_node.reinstallReinstalling a node (event end)
Integrating Managed Kubernetes with Container Registrycluster_registries_integration.init_createCreating a cluster integration (event start)
cluster_registries_integration.createCreating a cluster integration (event end)
cluster_registries_integration.init_delete_allDeleting all cluster integrations (event start)
cluster_registries_integration_delete_allDeleting all cluster integrations (event end)
cluster_registries_integration.init_deleteDeleting a cluster integration (event start)
cluster_registries_integration_deleteDeleting a cluster integration (event end)
cluster_registries_integration.init_updateUpdating a cluster integration (event start)
cluster_registries_integration_updateUpdating a cluster integration (event end)
Envoy Gateway applicationmks.cluster_addon_envoy_gateway.init_createInstalling Envoy Gateway cluster application (event start)
mks.cluster_addon_envoy_gateway.createInstalling Envoy Gateway cluster application (event end)
mks.cluster_addon_envoy_gateway.init_deleteDeleting Envoy Gateway cluster application (event start)
mks.cluster_addon_envoy_gateway.deleteDeleting Envoy Gateway cluster application (event end)

S3 service

Responsible for operations with S3. You can manage S3 via the Object Storage API, S3 API, and Swift API.

Event name (event_type)Description
Bucketss3.bucket.createCreating a bucket
s3.bucket.deleteDeleting a bucket
s3.bucket_meta.updateChanging bucket metadata
s3.bucket_expiring.updateChanging the Default-Delete-After header
s3.bucket_limits.updateChanging bucket limits
s3.bucket_publicity.enableChanging bucket type to public
s3.bucket_publicity.disableChanging bucket type to private
s3.bucket_versioning.enableEnabling bucket versioning
s3.bucket_versioning.suspendSuspending bucket versioning
s3.bucket_cors.setApplying bucket CORS rules
s3.bucket_cors.deleteDeleting bucket CORS rules
s3.bucket_custom_domain.addAdding a custom domain
s3.bucket_custom_domain.deleteDeleting a custom domain
s3.bucket_website.updateConfiguring a bucket website
s3.bucket_policy.setCreating an access policy
s3.bucket_policy.deleteDeleting an access policy
s3.bucket_cache_control.setAdding a Сache-Сontrol header
s3.bucket_cache_control.deleteDeleting a Сache-Сontrol header
s3.bucket_addressing.updateChanging bucket addressing from Path-Style to vHosted
TLS (SSL) certificatess3.certificate.uploadUploading a certificate
s3.certificate.updateUpdating a certificate
s3.certificate.deleteDeleting a certificate
Bucket public domainss3.public_domain.createCreating a domain
s3.public_domain.deleteDeleting a domain
s3.public_domain.bindBinding a domain to a bucket
s3.public_domain.unbindUnbinding a domain from a bucket
Cache clearings3.cache.flushRequest to clear the cache
Logss3.logs.dumpCreating a storage log dump
s3.logs.cancelCanceling a storage log dump creation

DBaaS service

Responsible for operations with Managed Databases.

Event name (event_type)Description
Clusterdbaas.cluster.createCreating a cluster
dbaas.cluster.updateUpdating a cluster
dbaas.cluster.deleteDeleting a cluster
dbaas.cluster.resizeScaling a cluster
dbaas.cluster_readonly_mode.enableSetting read-only mode
dbaas.cluster_readwrite_mode.enableSetting read-write mode
dbaas.cluster.lockLocking a cluster
dbaas.cluster.unlockUnlocking a cluster
Databasedbaas.cluster_database.createCreating a database
dbaas.cluster_database.updateUpdating a database
dbaas.cluster_database.deleteDeleting a database
Prometheus tokendbaas.prometheus_token.createCreating a token
dbaas.prometheus_token.updateUpdating a token
dbaas.prometheus_token.deleteDeleting a token
Node groupdbaas.cluster_node_group.createCreating a node group
dbaas.cluster_node_group.updateUpdating a node group
dbaas.cluster_node_group.deleteDeleting a node group
dbaas.cluster_node_group.resizeScaling a node group
Public IP addressdbaas.cluster_floating_ip.createCreating an IP address
dbaas.cluster_floating_ip.deleteDeleting an IP address
Kafka topicdbaas.cluster_database_topic.createCreating a topic
dbaas.cluster_database_topic.updateUpdating a topic
dbaas.cluster_database_topic.deleteDeleting a topic
Userdbaas.cluster_database_user.createCreating a user
dbaas.cluster_database_user.updateUpdating a user
dbaas.cluster_database_user.deleteDeleting a user
dbaas.cluster_database_user_password.updateChanging a user password
User accessdbaas.cluster_database_permission.createCreating access
dbaas.cluster_database_permission.deleteDeleting access
Access Control Lists (ACLs)dbaas.cluster_acl.createCreating an Access Control List
dbaas.cluster_acl.updateUpdating an Access Control List
dbaas.cluster_acl.deleteDeleting an Access Control List
Logical replication slotdbaas.cluster_database_logical_replication_slot.createCreating a logical replication slot
dbaas.cluster_database_logical_replication_slot.deleteDeleting a logical replication slot
Extensiondbaas.cluster_database_extension.createCreating an extension
dbaas.cluster_database_extension.deleteDeleting an extension