Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex BareMetal
    • All guides
    • Overview
    • Integrating with other Yandex Cloud services
      • Overview
      • Stock server configurations
      • Custom server configuration
      • On-request server configuration
      • Overview
      • Public network
      • Private network
      • DHCP
      • MC-LAG
      • Restrictions in BareMetal networks
      • Overview
      • Images
        • Overview
      • Access management
      • Additional server settings
      • Management console
      • Monitoring metrics
    • Quotas and limits
  • Pricing policy
  • FAQ

In this article:

  • Management event reference
  • Data event reference
  • flowlogs.ExternalFlow event
  1. Concepts
  2. Setup and management
  3. Audit Trails events
  4. Overview

Yandex Audit Trails event reference

Written by
Yandex Cloud
Updated at May 7, 2026
View in Markdown
  • Management event reference
  • Data event reference
    • flowlogs.ExternalFlow event

Audit Trails supports tracking control plane (management) and data plane (data) events for Yandex BareMetal.

The general format of the event_type field value is as follows:

yandex.cloud.audit.baremetal.<event_name>

You can find the detailed JSON structure of the event record in the audit log reference. The events in it are sorted alphabetically without division into levels and contain all possible fields. In real logs, the field set depends on the parameters of the event and particular object.

Management event referenceManagement event reference

Event name Description
ApplyUpdatePrivateCloudConnection Applying updates to a private connection to subnets in a VPC or on-prem infrastructure
BatchCreateServer Renting several BareMetal servers at the same time
CreateImage Creating a boot image
CreatePrivateCloudConnection Creating a private connection to subnets in a VPC or on-prem infrastructure
CreatePrivateSubnet Creating a private subnet
CreatePublicPrefixPool Creating a public prefix pool
CreatePublicSubnet Creating a public subnet
CreateServer BareMetal server rent
CreateVRF Creating a virtual network segment (VRF)
DeleteImage Deleting a boot image
DeletePrivateCloudConnection Deleting a private connection to subnets in a VPC or on-prem infrastructure
DeletePrivateSubnet Deleting a private subnet
DeletePublicPrefixPool Deleting a public prefix pool
DeletePublicSubnet Deleting a public subnet
DeleteServer Completely removing the BareMetal server, wiping disks and all user data
DeleteVRF Deleting a virtual network segment (VRF)
PowerOffServer Powering off a BareMetal server
PowerOnServer Powering on a BareMetal server
RebootServer Restarting a BareMetal server
RegisterServerBackupAgent Registering a Yandex Cloud Backup agent on a BareMetal server
ReinstallServer Reinstalling a BareMetal server OS
StartServerProlongation Enabling auto-renewal of BareMetal server lease
StopServerProlongation Disabling auto-renewal of BareMetal server rent
UpdateImage Updating a boot image
UpdatePrivateCloudConnection Updating a private connection to subnets in a VPC or on-prem infrastructure
UpdatePrivateSubnet Updating a private subnet
UpdatePublicPrefixPool Updating a public prefix pool
UpdatePublicSubnet Updating a public subnet
UpdateServer Updating a BareMetal server
UpdateVRF Updating a virtual network segment (VRF)

Data event referenceData event reference

Event name Description
flowlogs.ExternalFlow Traffic flow from BareMetal servers to external networks

flowlogs.ExternalFlow eventflowlogs.ExternalFlow event

The flowlogs.ExternalFlow event contains aggregate information about BareMetal server traffic streams to external networks.

Warning

ExternalFlow events are sampled from every 1,000th packet and aggregated for a five-minute interval.

The details object of a flowlogs.ExternalFlow event contains the following fields:

Field

Type

Description

vers

int64

IP version: 4 for IPv4 or 6 for IPv6

proto

int64

Transport protocol IANA number, e.g., 6 for TCP or 17 for UDP

srcAddr

string

Source IP address

dstAddr

string

Destination IP address

direction

string

Traffic direction, with INGRESS for incoming traffic and EGRESS for outgoing traffic

srcPort

int64

Source port

dstPort

int64

Destination port

aggStart

timestamp

Aggregation period start time in RFC 3339 format

aggEnd

timestamp

Aggregation period end time in RFC 3339 format

packets

int64

Number of packets for the aggregation period

bytes

int64

Number of bytes for the aggregation period

tcpFlags

string

TCP flags in hex format, e.g., 0x02

subnetId

string

Subnet ID

folderId

string

Folder ID

Was the article helpful?

Previous
Images
Next
ApplyUpdatePrivateCloudConnection
© 2026 Direct Cursus Technology L.L.C.