All Products
Search
Document Center

Security Center:DescribeCriteria

Last Updated:Sep 17, 2026

Queries the fuzzy match conditions for asset properties that can be displayed when you query assets.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:DescribeCriteria

get

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

MachineTypes

string

No

The Asset Type to query. Valid values:

  • ecs: queries all ECS servers.

ecs

Value

string

No

The fuzzy match value entered when querying assets.

47.96

SupportAutoTag

boolean

No

Specifies whether the fuzzy query field supports automatic matching. Default value: false. Valid values:

  • true: Supported.

  • false: Not supported.

true

ResourceDirectoryAccountId

integer

No

The ID of the Alibaba Cloud account of the member accounts in the resource folder.

Note

Invoke the DescribeMonitorAccounts operation to obtain this parameter.

127608589417****

Response elements

Element

Type

Description

Example

object

The response parameters.

RequestId

string

The request ID, which is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot issues.

8E6DDACF-99AF-5939-AFFD-FCCD3B01E724

CriteriaList

array<object>

The list of asset query conditions.

object

The asset query condition information.

Type

string

The type of the query condition. Valid values:

  • input: You must manually enter the query field.

  • select: You must select a subtype of the query condition from the drop-down list.

input

Name

string

The name of the query condition.

  • internetIp: public IP address.

  • intranetIp: private IP address.

  • instanceName: instance name.

  • instanceId: instance ID.

  • machineType: instance type.

  • clusterIdList: cluster ID list.

  • vpcInstanceId: VPC ID.

  • osName: operating system.

  • osType: system type.

  • hcStatus: whether baseline issues exist.

  • vulStatus: whether vulnerability issues exist.

  • asapVulStatus: whether high-priority vulnerabilities exist.

  • alarmStatus: whether security alerts exist.

  • riskStatus: whether risks exist.

  • clientStatus: whether the client is online.

  • clientSubStatus: client substatus.

  • runningStatus: running status.

  • tagName: tag name.

  • vendorAuthAlias: authorized account alias.

  • vendorUid: authorized account ID.

  • vendorUserName: authorized account name.

  • namespace: namespace.

  • appName: application name.

  • groupName: group name.

  • regionId: region.

  • groupId: group ID.

  • newInstance: whether the asset is newly added.

  • containerStatus: whether containers exist.

  • importance: asset importance.

  • exposedStatus: whether the server is exposed.

  • clusterId: cluster ID.

  • authVersion: authorization version.

  • flag: cloud provider.

  • ipList: IP list.

  • uuidList: UUID.

  • aiStatus: whether AI components exist.

  • tagKeyValue: ECS tag.

  • ecsType: server type.

  • alisecguardStatus: self-protection status.

  • alihipsStatus: AliHips status.

  • alinetStatus: AliNet status.

  • alidetectStatus: endpoint engine status.

  • yundunMonitorStatus: information collection component status.

  • clusterNodeStatus: whether the asset is a cluster node.

internetIp

Values

string

The specific asset property values that correspond to the fuzzy match value.

Note
  • When Name is machineType, the valid values are:

Note
  • 38: Elastic Container Instance.

  • 51: RunD container instance.

  • 52: RunC container instance.

  • When Name is osType, the valid values are:

Note
  • linux: Linux.

  • windows: Windows.

  • When Name is hcStatus, the valid values are:

Note
  • NO: No.

  • YES: Yes.

  • When Name is vulStatus, the valid values are:

Note
  • NO: No.

  • YES: Yes.

  • When Name is asapVulStatus, the valid values are:

Note
  • NO: No.

  • YES: Yes.

  • When Name is alarmStatus, the valid values are:

Note
  • NO: No.

  • YES: Yes.

  • When Name is riskStatus, the valid values are:

Note
  • NO: No.

  • YES: Yes.

  • UNKNOWN: Unknown.

  • When Name is clientStatus, the valid values are:

Note
  • online: Online.

  • offline: Offline.

  • pause: Protection paused.

  • When Name is clientSubStatus, the valid values are:

Note
  • online: Online.

  • offline: Offline.

  • pause: Protection paused.

  • stopped: Shut down.

  • uninstalled: Not installed.

  • When Name is runningStatus, the valid values are:

Note
  • Running: Running.

  • notRunning: Shut down.

  • UNKNOWN: Unknown.

  • When Name is importance, the valid values are:

Note
  • important: Important.

  • general: General.

  • test: Test.

  • When Name is containerStatus, the valid values are:

Note
  • NO: No.

  • YES: Yes.

  • When Name is exposedStatus, the valid values are:

Note
  • NO: No.

  • YES: Yes.

  • When Name is authVersion, the valid values are:

Note
  • 1: Free Edition.

  • 3: Enterprise Edition.

  • 5: Premium Edition.

  • 6: Anti-virus Edition.

  • 7: Ultimate Edition.

  • When Name is flag, the valid values are:

Note
  • 0|8|15: Alibaba Cloud.

  • 1: Non-cloud server.

  • 2: IDC.

  • 3: Tencent Cloud.

  • 4: Huawei Cloud.

  • 5: Azure.

  • 7: AWS.

  • 9: SAE.

  • 10: PAI.

  • 13: ACS.

  • 14: Volcengine.

  • 16: Google Cloud.

  • When Name is aiStatus, the valid values are:

Note
  • NO: No.

  • YES: Yes.

  • When Name is ecsType, the valid values are:

Note
  • 8: Simple application server.

  • 11: Lingjun.

  • 15: RDS Custom.

  • !8: Host server.

  • When Name is alisecguardStatus, the valid values are:

Note
  • 0: Plugin online.

  • 1: Not enabled.

  • 2: Plugin offline.

  • -99: Installation failed.

  • When Name is alihipsStatus, the valid values are:

Note
  • 0: Plugin online.

  • 1: Not enabled.

  • 2: Plugin offline.

  • -99: Installation failed.

  • When Name is alinetStatus, the valid values are:

Note
  • 0: Plugin online.

  • 1: Not enabled.

  • 2: Plugin offline.

  • -99: Installation failed.

  • When Name is alidetectStatus, the valid values are:

Note
  • 0: Plugin online.

  • 1: Not enabled.

  • 2: Plugin offline.

  • -99: Installation failed.

  • When Name is yundunMonitorStatus, the valid values are:

Note
  • 0: Plugin online.

  • 1: Not enabled.

  • 2: Plugin offline.

  • -99: Installation failed.

  • When Name is clusterNodeStatus, the valid values are:

Note
  • false: No.

  • true: Yes.

47.96.XX.XX

MultiValues

string

The structured property values of the asset that correspond to the fuzzy match value. The value is in JSON format and contains the following fields:

  • vendor: the provider.

  • regionIds: the supported regions.

[{"vendor":0,"regionIds":{"default":["ap-southeast-1","ap-northeast-2","ap-southeast-3","ap-southeast-5","ap-southeast-7","me-central-1"]}},{"vendor":1,"regionIds":{"default":["outside-of-aliyun"]}}]

Examples

Success response

JSON format

{
  "RequestId": "8E6DDACF-99AF-5939-AFFD-FCCD3B01E724",
  "CriteriaList": [
    {
      "Type": "input",
      "Name": "internetIp",
      "Values": "47.96.XX.XX",
      "MultiValues": "[{\"vendor\":0,\"regionIds\":{\"default\":[\"ap-southeast-1\",\"ap-northeast-2\",\"ap-southeast-3\",\"ap-southeast-5\",\"ap-southeast-7\",\"me-central-1\"]}},{\"vendor\":1,\"regionIds\":{\"default\":[\"outside-of-aliyun\"]}}]"
    }
  ]
}

Error codes

HTTP status code

Error code

Error message

Description

400 NoPermission no permission
400 RdCheckNoPermission Resource directory account verification has no permission.
500 ServerError ServerError
500 RdCheckInnerError Resource directory account service internal error.
403 NoPermission caller has no permission You are not authorized to do this operation.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.