Retrieves a list of predefined rules.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:ListCloudSiemPredefinedRules |
list |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| Id |
string |
No |
The rule ID. |
10223 |
| StartTime |
integer |
No |
The start of the time range to query. This value is a UNIX timestamp in milliseconds. |
1577808000000 |
| EndTime |
integer |
No |
The end of the time range to query. This value is a UNIX timestamp in milliseconds. |
1577808000000 |
| ThreatLevel |
array |
No |
The threat level. The value is a JSON array. Valid values:
|
["serious","suspicious","remind"] |
|
string |
No |
The threat level. The value is a JSON array. Valid values:
|
["remind","serious"] |
|
| AlertType |
string |
No |
The alert type. |
scan |
| RuleName |
string |
No |
The rule name. The name can contain only letters, digits, underscores (_), and periods (.). |
waf_scan |
| RuleType |
string |
No |
The rule type. Valid values:
|
customize |
| EventTransferType |
string |
No |
The event generation method. Valid values:
|
allToSingle |
| AttCk |
string |
No |
The ATT&CK technique. |
T1595.002 Vulnerability Scanning |
| LogSource |
string |
No |
The log source. |
cloud_siem_alb_flow_log |
| Status |
integer |
No |
The rule status. Valid values:
|
0 |
| OrderField |
string |
No |
The field to sort the rules by. Valid values:
|
Id |
| Order |
string |
No |
The sort order. Valid values:
|
desc |
| CurrentPage |
integer |
Yes |
The page number. The value must be greater than or equal to 1. |
1 |
| PageSize |
integer |
Yes |
The number of entries per page. The maximum value is 100. |
10 |
| RoleType |
integer |
No |
The view type.
|
1 |
| RoleFor |
integer |
No |
The user ID that the administrator uses to switch to the perspective of a member. |
113091674488**** |
| RegionId |
string |
No |
The region where the Data Management center of the threat analysis feature is located. Select the region where your assets are located. Valid values:
|
cn-hangzhou |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
PageResponse<List |
||
| Success |
boolean |
Indicates whether the request was successful. Valid values:
|
true |
| Code |
integer |
The HTTP status code. |
200 |
| Message |
string |
The returned message. |
success |
| RequestId |
string |
The request ID. |
9AAA9ED9-78F4-5021-86DC-D51C7511**** |
| Data |
object |
The data returned. |
123456 |
| PageInfo |
object |
The pagination information. |
|
| CurrentPage |
integer |
The page number. |
1 |
| PageSize |
integer |
The number of entries returned per page. |
10 |
| TotalCount |
integer |
The total number of entries. |
100 |
| ResponseData |
array<object> |
The detailed data. |
|
|
object |
|||
| Id |
integer |
The ID of the predefined rule. |
123456789 |
| GmtCreate |
string |
The time when the rule was created. |
2021-01-06 16:37:29 |
| GmtModified |
string |
The time when the rule was last modified. |
2021-01-06 16:37:29 |
| RuleName |
string |
The rule name. |
siem_base64-command-exec_aegis-proc |
| RuleNameCn |
string |
The Chinese name of the rule. |
siem_base64-command-exec_aegis-proc |
| RuleNameEn |
string |
The English name of the rule. |
siem_base64-command-exec_aegis-proc |
| RuleNameMds |
string |
The Medusa code of the rule name. |
${siem_rule_name_siem_cfw-attack-count-level-up_cfw-attack} |
| RuleDescMds |
string |
The Medusa code of the rule description. |
${siem_rule_description_siem_cfw-attack-count-level-up_cfw-attack} |
| ThreatLevel |
string |
The threat level. Valid values:
|
remind |
| AlertType |
string |
The threat type. |
WEBSHELL |
| Source |
string |
The log source of the rule. |
cloud_siem_aegis_proc |
| EventTransferType |
string |
The event generation method. Valid values:
|
allToSingle |
| AttCk |
string |
The ATT&CK technique. |
T1595.002 Vulnerability Scanning |
| Status |
integer |
The status of the predefined rule. Valid values:
|
0 |
Examples
Success response
JSON format
{
"Success": true,
"Code": 200,
"Message": "success",
"RequestId": "9AAA9ED9-78F4-5021-86DC-D51C7511****",
"Data": {
"PageInfo": {
"CurrentPage": 1,
"PageSize": 10,
"TotalCount": 100
},
"ResponseData": [
{
"Id": 123456789,
"GmtCreate": "2021-01-06 16:37:29",
"GmtModified": "2021-01-06 16:37:29",
"RuleName": "siem_base64-command-exec_aegis-proc",
"RuleNameCn": "siem_base64-command-exec_aegis-proc",
"RuleNameEn": "siem_base64-command-exec_aegis-proc",
"RuleNameMds": "${siem_rule_name_siem_cfw-attack-count-level-up_cfw-attack}",
"RuleDescMds": "${siem_rule_description_siem_cfw-attack-count-level-up_cfw-attack}",
"ThreatLevel": "remind",
"AlertType": "WEBSHELL",
"Source": "cloud_siem_aegis_proc",
"EventTransferType": "allToSingle",
"AttCk": "T1595.002 Vulnerability Scanning",
"Status": 0
}
]
}
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 500 | InternalError | The request processing has failed due to some unknown error. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.