Skip to Main Content
IBM Cloud - Structured Ideas


This portal is to open public enhancement requests against IBM Cloud and its products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

IBM Cloud Support Center (https://cloud.ibm.com/unifiedsupport/cases/form) – Use this site for any IBM Cloud defect or support need.

Stack Overflow (https://stackoverflow.com/questions/tagged/ibm-cloud) – Use this site for IBM Cloud technical Q&A using the tag "ibm-cloud".

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Functionality already exists
Created by Guest
Created on Sep 24, 2023

All Users IBM Cloud Activities Must be Recorder in Activity Logs and should be visible based on new RBAC policies

All Users IBM Cloud Activities Must be Recorded somewhere in IBM Cloud Activity Logs and should be visible based on new RBAC policies.

Reason - Indivisual users does individual tasks on various IBM cloud services but there is no single pane of glass, where all the activities can be monitored for security and compliance purpose. There could be further integrations with Monitoring services like certain type of activities should be mobitored exclusively via emails/texts/notifications (similarly Azure Activity Logs and its integration with Alerts based on Action Groups). 

Idea priority High
Needed By Month
  • Admin
    Warren Comiskey
    Reply
    |
    Feb 24, 2024

    Hi. IBM Cloud captures activity events and shares them back to the accounts. This is done through a combination of the Activity Tracker Event Router and Activity Tracker hosted search services. As a user within an account, those with appropriate RBAC may configure how the activity events are routed. Options include direct to a COS bucket, to Event Streams, or to the Activity Tracker hosted event search services. IBM Cloud shares thousands of different events. A good single location starting point for the different events is here.


    Activity Events are captured at the account level. The events land in defined regions unless users adjust the event routing to other regions. Location based events land in the region they originated. If a vcenter service is modified in a given region, the events land in that region by default. Global events land in Frankfurt by default, and can be routed to alternate regions as configured by the account user. Examples of global events are security based events, or events that may span 1 or more region at the same time. If your region of use is not Frankfurt it is possible the events you are seeking are still landing by default in Frankfurt. Document for how to route the events is here or you may alternatively elect to maintain a service instance in Frankfurt. The default for global events landing in Frankfurt is to ensure data maintains the appropriate GDPR compliance and under EU management if this compliance is applicable to you. If not, setup a route and forward it to your target region of choice.

    Activity Tracker hosted event search may be selected as a service to manage activity events. Users can provision and configure a service instance to store events for 7, 14, and 30 days in an indexed search. Users can configure alerts, parse, chart and query events. It is also possible to re-route data from within this service. Access to events can be managed through the service with IAM level controls.

  • Guest
    Reply
    |
    Jan 18, 2024

    What additional information do we need here? Let me know, it is a simple governance non-compliance issue.

  • Guest
    Reply
    |
    Dec 6, 2023

    Hello,


    Logs are absolutely not helpful. There should be straight activity logs at account level which can be further drilled down to the resources based on the events. currently, I have no idea who created the cos buckets, created the route table, edited the table or security group. edited/resized the VM, created a new disk in VPC and power. so all these things can be solved.

  • Admin
    GILLY DEKEL
    Reply
    |
    Sep 27, 2023

    Hello and thank you for your submission ! We were hoping that you could provide some additional clarity - is the issue that there are events that are missing from the logs, and if so can you provide examples? Or is it a single pane of glass across things like logging, monitoring and activity tracker?


    Thank you for your clarification !