Creates a whitelist rule to suppress sensitive file alerts in agentless detection.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:CreateMaliciousFileWhitelistConfig |
create |
*MaliciousFileWhitelistConfig
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| EventName |
string |
No |
Alert name:
|
ALL |
| Field |
string |
No |
Field to match for whitelisting sensitive file alerts. |
fileMd5 |
| Operator |
string |
No |
Rule comparison operator:
|
strEqual |
| FieldValue |
string |
No |
Expected value of the field to match. |
b2cf9747ee49d8d9b105cf16e078cc16 |
| TargetType |
string |
No |
Effective scope:
|
ALL |
| TargetValue |
string |
No |
Scope of targeted assets:
|
ALL |
| Source |
string |
No |
Detection source:
|
agentless |
| Remark |
string |
No |
Remarks. |
whitelist |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
PlainResult |
||
| Data |
object |
Response data. |
|
| GmtCreate |
string |
Creation time. |
1671607025000 |
| GmtModified |
string |
Modification time. |
1671607025000 |
| EventName |
string |
Alert name:
|
ALL |
| Field |
string |
Whitelisted field. |
fileMd5 |
| FieldValue |
string |
Whitelisted field value. |
b2cf9747ee49d8d9b105cf16e078cc16 |
| Operator |
string |
Rule comparison operator:
|
strEqual |
| TargetValue |
string |
Scope of targeted assets:
|
ALL |
| TargetType |
string |
Effective scope:
|
ALL |
| Count |
string |
Number of targeted assets. Note
This field is returned only when TargetType is set to SELECTION_KEY. |
1 |
| Source |
string |
Detection source:
|
agentless |
| Id |
string |
Rule ID. |
1 |
| Success |
boolean |
Indicates whether the call succeeded.
|
true |
| Code |
string |
API status code. |
200 |
| Message |
string |
Response message. |
successful |
| RequestId |
string |
Request ID. Use this ID for troubleshooting. |
A4EB8B1C-1DEC-5E18-BCD0-XXXXXXXXX |
| HttpStatusCode |
integer |
HTTP status code. |
200 |
Examples
Success response
JSON format
{
"Data": {
"GmtCreate": "1671607025000",
"GmtModified": "1671607025000",
"EventName": "ALL",
"Field": "fileMd5",
"FieldValue": "b2cf9747ee49d8d9b105cf16e078cc16",
"Operator": "strEqual",
"TargetValue": "ALL",
"TargetType": "ALL",
"Count": "1",
"Source": "agentless",
"Id": "1"
},
"Success": true,
"Code": "200",
"Message": "successful",
"RequestId": "A4EB8B1C-1DEC-5E18-BCD0-XXXXXXXXX",
"HttpStatusCode": 200
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | NoPermission | no permission | |
| 400 | UnknownError | UnknownError | |
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission | You are not authorized to do this operation. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.