Adds a log collection task to import log data into Threat Analysis for alerting and event analysis.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:AddUserSourceLogConfig |
create |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| SourceProdCode |
string |
No |
The code of the product. |
sas |
| SourceLogCode |
string |
No |
The code of the log. |
cloud_siem_aegis_proc |
| SubUserId |
integer |
Yes |
The ID of the Alibaba Cloud account for which you want to collect logs. |
123XXXXXX |
| SourceLogInfo |
string |
Yes |
The detailed information about the Simple Log Service (SLS) log to be collected. The value is a JSON string. |
{"project":"wafnew-project-1335759343513432-cn-hangzhou","logStore":"wafnew-logstore","regionCode":"cn-hangzhou","prodCode":"waf"} |
| DisPlayLine |
string |
No |
The detailed information about the SLS log to be collected. |
cn-shanghai.siem-project.siem-logstore |
| Deleted |
integer |
No |
Specifies whether to add or delete the log collection task. Valid values:
|
0 |
| RegionId |
string |
No |
The region where the Data Management center of Threat Analysis is located. Select a region based on the region where your assets reside. Valid values:
|
cn-hangzhou |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
CloudSiemSuccessResponse |
||
| Data |
object |
The return value of the request. |
|
| DiplayLine |
string |
The detailed information about the SLS log. |
cn-shanghai.siem-project.siem-logstore |
| SourceProdCode |
string |
The code of the product. |
sas |
| SourceLogCode |
string |
The code of the log. |
cloud_siem_aegis_proc |
| Displayed |
boolean |
Indicates whether the details of the log collection task are returned. Valid values: |
0 |
| Imported |
boolean |
Indicates whether the log is collected. Valid values: |
0 |
| MainUserId |
integer |
The ID of the Alibaba Cloud account that is used to purchase Threat Analysis. |
123XXXXXXXXX |
| SubUserId |
integer |
The ID of the Alibaba Cloud account for which the logs are collected. |
123XXXXXXXX |
| SubUserName |
string |
The name of the Alibaba Cloud account for which the logs are collected. |
sas_account_xxx |
| RequestId |
string |
The ID of the request. |
6276D891-*****-55B2-87B9-74D413F7**** |
Examples
Success response
JSON format
{
"Data": {
"DiplayLine": "cn-shanghai.siem-project.siem-logstore",
"SourceProdCode": "sas",
"SourceLogCode": "cloud_siem_aegis_proc",
"Displayed": true,
"Imported": true,
"MainUserId": 0,
"SubUserId": 0,
"SubUserName": "sas_account_xxx"
},
"RequestId": "6276D891-*****-55B2-87B9-74D413F7****"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 500 | InternalError | The request processing has failed due to some unknown error. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.