Retrieves the details of a specific alert exception. An alert event consists of an alert and multiple associated exceptions.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:DescribeSuspEventDetail |
get |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| SourceIp |
string |
No |
The source IP address of the request. |
121.33.XX.XX |
| Lang |
string |
No |
The language of the request and response content. Default value: zh. Valid values:
|
zh |
| SuspiciousEventId |
integer |
Yes |
The ID of the exception. |
32750999 |
| From |
string |
Yes |
The data source of the exception. Set the value to sas. |
sas |
| ResourceDirectoryAccountId |
integer |
No |
The Alibaba Cloud account ID of the member in the resource directory. Note
You can call the DescribeMonitorAccounts operation to query the ID. |
16670360956***** |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The data returned. |
||
| DataSource |
string |
The data source of the exception. |
aegis_suspicious_**** |
| EventName |
string |
The name of the exception. |
WEBSHELL |
| InternetIp |
string |
The public IP address of the server on which the exception was detected. |
101.132.XX.XX |
| AlarmUniqueInfo |
string |
The unique ID of the alarm event. Note
To query anomaly information for a single alarm event, provide the unique ID, which you can obtain by calling the DescribeSuspEvents operation. |
8df914418f4211fb**** |
| IntranetIp |
string |
The private IP address of the server on which the exception was detected. |
172.26.XX.XX |
| LastTime |
string |
The time when the exception was last detected. |
2018-10-30 11:43:46 |
| OperateMsg |
string |
The handling result message for the exception. |
success |
| Uuid |
string |
The UUID of the server on which the exception was detected. |
bffb12c3-590a-4db2-b538-**** |
| CanBeDealOnLine |
boolean |
Indicates whether the exception can be handled online, such as blocking, whitelisting, or ignoring it. Valid values:
|
true |
| RequestId |
string |
The ID of the request. |
0B48AB3C-84FC-424D-A01D-B9270EF46038 |
| EventTypeDesc |
string |
The type of the exception. |
Malicious Software-Variable Trojan |
| EventDesc |
string |
The description of the exception. |
The detection model found a suspicious Webshell file on your server, which may be a backdoor file implanted to maintain permissions after the attacker successfully invaded the website. |
| InstanceName |
string |
The name of the server on which the exception was detected. |
ca_cpm_**** |
| EventStatus |
string |
The status of the exception. Valid values:
|
1 |
| SaleVersion |
string |
The Security Center edition that can detect the exception. Valid values:
|
1 |
| OperateErrorCode |
string |
The handling result code for the exception. |
quara.Succes |
| Level |
string |
The risk level of the exception. Valid values:
|
serious |
| Id |
integer |
The ID of the exception. |
11416624 |
| Details |
array<object> |
The exception details. |
|
|
object |
The details of the exception. |
||
| Type |
string |
The format in which the details of the exception are displayed. Valid values:
|
html |
| Value |
string |
The attribute information about the exception. For example, for an unusual logon alert, this includes the logon time and source location. For a webshell alert, this includes the trojan file path and type. |
getopt |
| NameDisplay |
string |
The display name of the alert event. |
Trojan Path |
Examples
Success response
JSON format
{
"DataSource": "aegis_suspicious_****",
"EventName": "WEBSHELL",
"InternetIp": "101.132.XX.XX",
"AlarmUniqueInfo": "8df914418f4211fb****",
"IntranetIp": "172.26.XX.XX",
"LastTime": " 2018-10-30 11:43:46 ",
"OperateMsg": "success",
"Uuid": "bffb12c3-590a-4db2-b538-****",
"CanBeDealOnLine": true,
"RequestId": "0B48AB3C-84FC-424D-A01D-B9270EF46038",
"EventTypeDesc": "Malicious Software-Variable Trojan",
"EventDesc": "The detection model found a suspicious Webshell file on your server, which may be a backdoor file implanted to maintain permissions after the attacker successfully invaded the website.",
"InstanceName": "ca_cpm_****",
"EventStatus": "1",
"SaleVersion": "1",
"OperateErrorCode": "quara.Succes",
"Level": "serious",
"Id": 11416624,
"Details": [
{
"Type": "html",
"Value": "getopt",
"NameDisplay": "Trojan Path"
}
]
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | UnknownError | UnknownError | |
| 400 | DataExists | %s data exist | |
| 400 | RdCheckNoPermission | Resource directory account verification has no permission. | |
| 500 | ServerError | ServerError | |
| 500 | RdCheckInnerError | Resource directory account service internal error. | |
| 403 | NoPermission | caller has no permission | You are not authorized to do this operation. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.