Error codes
|
HTTP status code |
Error code |
Error message |
Description |
Action |
| 400 | AccessKey.NotFound | Access Key not found, please add access key for siem. | No valid AccessKey pair found. Configure the %s account in the Security Center configuration center and grant permissions to SIEM. | diagnosis |
| 400 | AssumeRoleError | Specified role "AliyunServiceRoleForSasCloudSiem" is not exists. | The service-linked role AliyunServiceRoleForSasCloudSiem is missing. | diagnosis |
| 400 | CloudSiemCustomizeRuleDuplicateRuleNameExcepiton | The rule name is duplicated. | The custom rule name conflicts with an existing name. Rename the rule. | diagnosis |
| 400 | Datasets with associated references cannot be deleted | Delete the dataset-related references before attempting to delete the current dataset. | Delete all references to the dataset before deleting the dataset. | diagnosis |
| 400 | Expired.Log | CloudFireWall Alert Log is expired, please select CloudFireWall Real-Time Alert Log. | Cloud Firewall alert logs are scheduled for deprecation. Use Cloud Firewall real-time alert logs instead. | diagnosis |
| 403 | Forbidden.UserDenied.RdAccount | Forbidden User. | The current user is a resource directory user. Contact the administrator to be added as a delegated administrator for threat analysis. | diagnosis |
| 400 | ForbiddenAction | Unknown error. | The operation is invalid. | diagnosis |
| 400 | ForbiddenOperation | Please stop log import task. | Delete the task connection first. | diagnosis |
| 400 | IllegalParameter | The specified parameter %s is not valid, only support %s. | The specified parameter %s is not valid, only support %s | diagnosis |
| 500 | InternalError | The request processing has failed due to some unknown error. | An unknown error occurred in the service. Try again later. | diagnosis |
| 400 | InvalidOperation | Accesskey %s already bound. | AccessKey %s is already bound. | diagnosis |
| 400 | InvalidOperation | Access key %s already bound. | The AccessKey pair is already bound to account %. | diagnosis |
| 400 | InvalidParameter | The specified parameter %s is not valid. | The parameter is invalid. | diagnosis |
| 400 | InvalidUpdateRecord.Conflict | Only one of selectedEntityList or unSelectedEntityList can be specified. | The user failed during the automatic response process. | diagnosis |
| 400 | Need.CfwFlowLog | Cloud FireWall Real-Time Alert Log is dependency Cloud FireWall Flow Log. Please open Cloud FireWall Flow Log for account %s first. | Cloud Firewall real-time alert logs depend on Cloud Firewall flow logs. Connect the Cloud Firewall flow logs for account %s first. | diagnosis |
| 400 | NeedCfwFlowLog | Cloud Firewall Traffic Log must be integrated first. | Cloud Firewall real-time alert logs depend on Cloud Firewall flow logs. Connect the Cloud Firewall flow logs first. | diagnosis |
| 403 | OrderExpired | Siem Order Not Found. | No valid threat analysis order exists. | diagnosis |
| 500 | RamAssumeException | The request processing has failed due to ram service error. | Role assumption failed. | diagnosis |
| 400 | Siem.Analysis.IllegalParameter | Start time should less than or equal to end time. | The start time of the log query cannot be earlier than the end time. | diagnosis |
| 400 | Siem.Analysis.SQLError | Analysis SQL is error. | The SQL statement for query analysis contains a syntax error. | diagnosis |
| 500 | Siem.Delivery.ErrorMapping | The Mapping between productCode and logCode is error. | The product code and log code in the request parameters are inconsistent. | diagnosis |
| 500 | Siem.Delivery.ErrorProductCode | ProductCode is error for this action. | The product code in the current request is invalid. It is not in the product list supported by threat analysis. | diagnosis |
| 400 | Siem.Delivery.MissingProductCode | ProductCode is mandatory for this action. | The ProductCode parameter is missing during Operation logs delivery. | diagnosis |
| 400 | SIEM.Region.Duplicate | The region can be set only once. | The region can be set only once. | diagnosis |
| 500 | Siem.Storage.Exception | The request timed out, try again. | Retrieving storage information timed out. | diagnosis |
| 400 | Siem.TTL.Limit | TTL should be set 30 days at least. | The log retention period for threat analysis must be at least 30 days. | diagnosis |
| 500 | Sls.Delivery.Error | SLS service is unavailable. | Simple Log Service is abnormal. The threat analysis log delivery failed. | diagnosis |
| 400 | SLS.Index.Lost | The SLS project initialization will take a few minutes, try again later. | Index creation in Simple Log Service takes a few minutes. Try again later. | diagnosis |
| 500 | SLS.Operation.Error | SLS service is unavailable. | An error occurred when accessing Simple Log Service. | diagnosis |
| 400 | SLS.Project.Lost | The SLS project initialization will take a few minutes, try again later. | Simple Log Service initialization takes a few minutes. Try again later. | diagnosis |
| 500 | SLS.Ship.Error | The Simple Log Service about data shipping is unavailable. | Log delivery to Simple Log Service failed. | diagnosis |
| 500 | SLS.Sls4Service.Error | The Simple Log Service about embedding console pages is unavailable. | The Simple Log Service embedded console is inaccessible. | diagnosis |
| 500 | UserDeliveryFailed | failed in opening log delivery. | Failed to enable log delivery. | diagnosis |
| 400 | Siem.Delivery.ErrorMapping | The Mapping between productCode and logCode is error. | The product code and log code in the request parameters are inconsistent. | diagnosis |
| 400 | Sls.Delivery.Error | SLS service is unavailable. | Simple Log Service is abnormal. The threat analysis log delivery failed. | diagnosis |
| 400 | Siem.Delivery.ErrorProductCode | ProductCode is error for this action. | The product code in the current request is invalid. It is not in the product list supported by threat analysis. | diagnosis |