Queries the download information of a quarantined file for a security alert.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:DescribeQuaraFileDownloadInfo |
get |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| QuaraFileId |
integer |
No |
The ID of the quarantined file. Note
If you do not specify this parameter, calling the RollbackSuspEventQuaraFile operation does not cancel the quarantine of the file in the quarantine box, which means the call does not take effect. Call the DescribeSuspEventQuaraFiles operation to obtain the quarantined file ID (the value of the Id parameter). QuaraFileId depends on the following prerequisite chain: (1) The SAS Agent must be installed on the ECS instance and be online. (2) The Agent must detect a malicious file and generate a security alert. (3) The alert must be quarantined by calling the HandleSecurityEvents operation (OperationCode=quara). (4) Call the DescribeSuspEventQuaraFiles operation to obtain the QuaraFileId. Note: This parameter is actually required. If it is not provided, the API returns error code -101 (400) with the message "The ID of the file to be rolled back is not provided". |
123 |
| From |
string |
No |
The identifier of the request source. Set the value to sas. |
sas |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| Uuid |
string |
The unique identifier of the asset. |
4fe8e1cd-3c37-4851-b9de-124da32c**** |
| QuaraFileId |
integer |
The ID of the quarantined file. |
123 |
| RequestId |
string |
The request ID. |
29874225-EAAC-5415-8501-32DD20FXXXXX |
| DownloadUrl |
string |
The download URL. The URL is valid for 5 minutes. |
https://xxxxxxxx.oss-cn-hangzhou-1.aliyuncs.com/xxxxx/xxxxxxxxxxxxxx?Expires=1671448125&OSSAccessKeyId=xxx |
| Path |
string |
The file path. |
/etc/test |
| Md5 |
string |
The MD5 hash of the file. |
bb62ef1311bc564377a0378d3axxxxxx |
| Tag |
string |
The tag of the alert record. |
6d4ff40a22b15c86adecf2aa48xxxxx |
Examples
Success response
JSON format
{
"Uuid": "4fe8e1cd-3c37-4851-b9de-124da32c****",
"QuaraFileId": 123,
"RequestId": "29874225-EAAC-5415-8501-32DD20FXXXXX",
"DownloadUrl": "https://xxxxxxxx.oss-cn-hangzhou-1.aliyuncs.com/xxxxx/xxxxxxxxxxxxxx?Expires=1671448125&OSSAccessKeyId=xxx",
"Path": "/etc/test",
"Md5": "bb62ef1311bc564377a0378d3axxxxxx",
"Tag": "6d4ff40a22b15c86adecf2aa48xxxxx"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission | You are not authorized to do this operation. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.