All Products
Search
Document Center

Security Center:Public error codes

Last Updated:Jul 15, 2026

Error codes

HTTP status code

Error code

Error message

Description

Action

400 AccessKey.NotFound Access Key not found, please add access key for siem. No valid AccessKey pair found. Configure the %s account in the Security Center configuration center and grant permissions to SIEM. diagnosis
400 AssumeRoleError Specified role "AliyunServiceRoleForSasCloudSiem" is not exists. The service-linked role AliyunServiceRoleForSasCloudSiem is missing. diagnosis
400 CloudSiemCustomizeRuleDuplicateRuleNameExcepiton The rule name is duplicated. The custom rule name conflicts with an existing name. Rename the rule. diagnosis
400 Datasets with associated references cannot be deleted Delete the dataset-related references before attempting to delete the current dataset. Delete all references to the dataset before deleting the dataset. diagnosis
400 Expired.Log CloudFireWall Alert Log is expired, please select CloudFireWall Real-Time Alert Log. Cloud Firewall alert logs are scheduled for deprecation. Use Cloud Firewall real-time alert logs instead. diagnosis
403 Forbidden.UserDenied.RdAccount Forbidden User. The current user is a resource directory user. Contact the administrator to be added as a delegated administrator for threat analysis. diagnosis
400 ForbiddenAction Unknown error. The operation is invalid. diagnosis
400 ForbiddenOperation Please stop log import task. Delete the task connection first. diagnosis
400 IllegalParameter The specified parameter %s is not valid, only support %s. The specified parameter %s is not valid, only support %s diagnosis
500 InternalError The request processing has failed due to some unknown error. An unknown error occurred in the service. Try again later. diagnosis
400 InvalidOperation Accesskey %s already bound. AccessKey %s is already bound. diagnosis
400 InvalidOperation Access key %s already bound. The AccessKey pair is already bound to account %. diagnosis
400 InvalidParameter The specified parameter %s is not valid. The parameter is invalid. diagnosis
400 InvalidUpdateRecord.Conflict Only one of selectedEntityList or unSelectedEntityList can be specified. The user failed during the automatic response process. diagnosis
400 Need.CfwFlowLog Cloud FireWall Real-Time Alert Log is dependency Cloud FireWall Flow Log. Please open Cloud FireWall Flow Log for account %s first. Cloud Firewall real-time alert logs depend on Cloud Firewall flow logs. Connect the Cloud Firewall flow logs for account %s first. diagnosis
400 NeedCfwFlowLog Cloud Firewall Traffic Log must be integrated first. Cloud Firewall real-time alert logs depend on Cloud Firewall flow logs. Connect the Cloud Firewall flow logs first. diagnosis
403 OrderExpired Siem Order Not Found. No valid threat analysis order exists. diagnosis
500 RamAssumeException The request processing has failed due to ram service error. Role assumption failed. diagnosis
400 Siem.Analysis.IllegalParameter Start time should less than or equal to end time. The start time of the log query cannot be earlier than the end time. diagnosis
400 Siem.Analysis.SQLError Analysis SQL is error. The SQL statement for query analysis contains a syntax error. diagnosis
500 Siem.Delivery.ErrorMapping The Mapping between productCode and logCode is error. The product code and log code in the request parameters are inconsistent. diagnosis
500 Siem.Delivery.ErrorProductCode ProductCode is error for this action. The product code in the current request is invalid. It is not in the product list supported by threat analysis. diagnosis
400 Siem.Delivery.MissingProductCode ProductCode is mandatory for this action. The ProductCode parameter is missing during Operation logs delivery. diagnosis
400 SIEM.Region.Duplicate The region can be set only once. The region can be set only once. diagnosis
500 Siem.Storage.Exception The request timed out, try again. Retrieving storage information timed out. diagnosis
400 Siem.TTL.Limit TTL should be set 30 days at least. The log retention period for threat analysis must be at least 30 days. diagnosis
500 Sls.Delivery.Error SLS service is unavailable. Simple Log Service is abnormal. The threat analysis log delivery failed. diagnosis
400 SLS.Index.Lost The SLS project initialization will take a few minutes, try again later. Index creation in Simple Log Service takes a few minutes. Try again later. diagnosis
500 SLS.Operation.Error SLS service is unavailable. An error occurred when accessing Simple Log Service. diagnosis
400 SLS.Project.Lost The SLS project initialization will take a few minutes, try again later. Simple Log Service initialization takes a few minutes. Try again later. diagnosis
500 SLS.Ship.Error The Simple Log Service about data shipping is unavailable. Log delivery to Simple Log Service failed. diagnosis
500 SLS.Sls4Service.Error The Simple Log Service about embedding console pages is unavailable. The Simple Log Service embedded console is inaccessible. diagnosis
500 UserDeliveryFailed failed in opening log delivery. Failed to enable log delivery. diagnosis
400 Siem.Delivery.ErrorMapping The Mapping between productCode and logCode is error. The product code and log code in the request parameters are inconsistent. diagnosis
400 Sls.Delivery.Error SLS service is unavailable. Simple Log Service is abnormal. The threat analysis log delivery failed. diagnosis
400 Siem.Delivery.ErrorProductCode ProductCode is error for this action. The product code in the current request is invalid. It is not in the product list supported by threat analysis. diagnosis