Adds or updates alert whitelist rules.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:UpdateWhiteRuleList |
update |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| WhiteRuleId |
integer |
Yes |
The unique ID of the whitelist rule. |
123456789 |
| IncidentUuid |
string |
No |
The global unique ID of the event. |
85ea4241-798f-4684-a876-65d4f0c3**** |
| Expression |
string |
Yes |
The alert whitelist rule. This is a JSON object. |
[ { "alertName": "webshell", "alertNameId": "webshell", "alertType": "command", "alertTypeId": "command", "expression": { "status": 1, "conditions": [ { "isNot": false, "left": { "value": "file_path" }, "operator": "gt", "right": { "value": "cp" } } ] } } ] |
| RoleType |
integer |
No |
The view type.
|
1 |
| RoleFor |
integer |
No |
The user ID of the member. This parameter is used when an administrator switches to the perspective of a member. |
113091674488**** |
| RegionId |
string |
No |
The region of the Data Management center for threat analysis. Select a region for the Data Management center based on the region of your assets. Valid values:
|
cn-hangzhou |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
BaseResponse |
||
| Data |
any |
The return value of the request. |
123456 |
| Success |
boolean |
Indicates whether the request was successful. Valid values:
|
true |
| Code |
integer |
The status code of the request. |
200 |
| Message |
string |
The message returned for the request. |
success |
| RequestId |
string |
The request ID. |
9AAA9ED9-78F4-5021-86DC-D51C7511**** |
Examples
Success response
JSON format
{
"Data": "123456",
"Success": true,
"Code": 200,
"Message": "success",
"RequestId": "9AAA9ED9-78F4-5021-86DC-D51C7511****"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 500 | InternalError | The request processing has failed due to some unknown error. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.