Queries the auto-whitelist rules for security alerts.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:DescribeSecurityEventMarkMissList |
get |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| SourceIp |
string |
No |
The IP address of the access source. |
125.210.XX.XX |
| EventName |
string |
No |
The alert event name (child class). |
Login with unusual location |
| Remark |
string |
No |
The asset search keyword. You can enter the IP address, public IP address, private IP address, or asset name for fuzzy matching. |
192.168.XX.XX |
| CurrentPage |
integer |
Yes |
The page number of the page to return. Default value: 1, which indicates that the first page is returned. |
1 |
| PageSize |
integer |
Yes |
The number of whitelist rules to display on each page in a paged query. Default value: 20, which indicates that 20 whitelist rules are displayed on each page. |
20 |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| RequestId |
string |
The request ID, which is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot issues. |
24A20733-10A0-4AF6-BE6B-E3322413BB68 |
| PageInfo |
object |
The pagination information. |
|
| CurrentPage |
integer |
The page number of the current page in a paged query. |
1 |
| PageSize |
integer |
The number of whitelist rules to display on each page in a paged query. Default value: 20, which indicates that 20 whitelist rules are displayed on each page. |
20 |
| TotalCount |
integer |
The total number of whitelist rules returned. |
200 |
| Count |
integer |
The number of whitelist rules on the current page. |
9 |
| List |
array<object> |
The list of whitelist rules. |
|
|
object |
The whitelist rule information. |
||
| EventName |
string |
The alert event name (child class). |
Login with unusual location |
| InternetIp |
string |
The public IP address of the server. |
8.210.XX.XX |
| EventNameOriginal |
string |
The alert event name (parent class). |
login_common_location |
| AliUid |
integer |
The user ID. |
176618589410**** |
| FieldValue |
string |
The whitelist value. |
root |
| InstanceId |
string |
The server instance ID. |
rm-bp1e8t4q15sr3**** |
| Field |
string |
The whitelist field. |
type |
| IntranetIp |
string |
The private IP address of the server. |
172.25.XX.XX |
| FiledAliasName |
string |
The alias of the whitelist field. |
Logon Time |
| Uuid |
string |
The UUID of the asset instance. |
49e25e0f-bb51-4a5a-a1b3-13a4ddaa**** |
| Operate |
string |
The operator. Valid values:
|
contains |
| EventTypeOriginal |
string |
The alert event type (parent class). |
login_common_location |
| EventType |
string |
The alert event type (child class). |
Unusual Logon |
| InstanceName |
string |
The instance name of the asset. |
sql-test-001 |
| Id |
integer |
The ID of the alert whitelist rule. |
104037 |
Examples
Success response
JSON format
{
"RequestId": "24A20733-10A0-4AF6-BE6B-E3322413BB68",
"PageInfo": {
"CurrentPage": 1,
"PageSize": 20,
"TotalCount": 200,
"Count": 9
},
"List": [
{
"EventName": "Login with unusual location",
"InternetIp": "8.210.XX.XX",
"EventNameOriginal": "login_common_location",
"AliUid": 0,
"FieldValue": "root",
"InstanceId": "rm-bp1e8t4q15sr3****",
"Field": "type",
"IntranetIp": "172.25.XX.XX",
"FiledAliasName": "Logon Time",
"Uuid": "49e25e0f-bb51-4a5a-a1b3-13a4ddaa****",
"Operate": "contains",
"EventTypeOriginal": "login_common_location",
"EventType": "Unusual Logon",
"InstanceName": "sql-test-001",
"Id": 104037
}
]
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.