All Products
Search
Document Center

Security Center:DescribeSuspEvents

Last Updated:Sep 11, 2026

Queries a list of security alert events that have not been aggregated.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:DescribeSuspEvents

get

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

SourceIp

string

No

The IP address of the access source.

192.168.XX.XX

Dealed

string

No

Specifies whether the alert events to query have been handled. Valid values:

  • N: Unhandled.

  • Y: Handled.

N

Name

string

No

The name of the asset affected by the alert event.

ecs-xxx

Levels

string

No

The severity levels of the alert events to query. Separate multiple severity levels with commas (,). The severity levels are listed in descending order. Valid values:

  • serious: Urgent.

  • suspicious: Suspicious.

  • remind: Reminder.

serious

ParentEventTypes

string

No

The alerting type of the alert events to query. Valid values:

  • Abnormal process behavior

  • Web shell

  • Unusual logon

  • Abnormal event

  • Sensitive file tampering

  • Malicious process (cloud scan)

  • Suspicious network connectivity

  • Abnormal account

  • Application intrusion event

  • Cloud service threat detection

  • Precise defense

  • Application whitelist

  • Persistent backdoor

  • Web application threat detection

  • Malicious script

  • Threat intelligence

  • Malicious network behavior

  • Container cluster exception

  • Web shell (local scan)

  • Vulnerability exploits

  • Malicious process (local scan)

  • Trusted exception

  • Other

other

EventNames

string

No

The subtypes of the alert events. Separate multiple subtypes with commas (,).

WEBSHELL

Remark

string

No

The alert name or asset information to query.

Note

Fuzzy match is supported. Asset information includes the asset name, public IP address, and private IP address.

192.168.XX.XX

Status

string

No

The status of the alert events to query. Valid values:

  • 0: All.

  • 1: Unhandled.

  • 2: Ignored.

  • 4: Confirmed.

  • 8: Marked as false positive.

  • 16: Handling.

  • 32: Handled.

  • 64: Expired.

  • 128: Deleted.

  • 512: Automatic blocking in progress.

  • 513: Automatic blocking completed.

1

PageSize

string

No

The number of alert events to display on each page in a paged query. Default value: 20, which indicates that 20 alert events are displayed on each page. Maximum value: 100.

20

CurrentPage

string

No

The page number of the page to return in a paged query. Default value: 1, which indicates that the results start from page 1.

1

Lang

string

No

The language of the request and response. Default value: zh. Valid values:

  • zh: Chinese.

  • en: English.

zh

AlarmUniqueInfo

string

No

The unique ID of the alert event.

Note

To query the exception information of a single alert event, provide the unique ID of the alert event. You can obtain this ID by calling the DescribeSuspEvents operation.

8df914418f4211fb****

UniqueInfo

string

No

The unique key of the security alert.

73fc06fb175a7405697e402f52864****

Id

integer

No

The unique ID that identifies the alert event record.

123

From

string

No

The data source identifier of the alert event. The value is fixed as sas.

sas

Source

string

No

The alert source.

aegis_suspicious_file_v2

GroupId

integer

No

The group ID of the asset affected by the alert event.

18768

Uuids

string

No

The UUIDs of the servers for which you want to query alerts. Separate multiple UUIDs with commas (,).

bb5d2484-f10e-450d-8917-3e79667e****,0e7c2fcd-7100-42c7-a21a-db6e4f32****

ClusterId

string

No

The cluster ID for which you want to query alert events.

c4af4fdf38a98496a9b63c2be5dae****

ContainerFieldName

string

No

The container search field. Valid values:

  • instanceId: instance ID

  • appName: application name

  • clusterId: cluster ID

  • regionId: region

  • nodeName: node name

  • namespace: namespace

  • clusterName: cluster name

  • image: image name

  • imageRepoName: image repository name

  • imageRepoNamespace: image repository namespace

  • imageRepoTag: image tag

  • imageDigest: image digest

instanceId

ContainerFieldValue

string

No

The value of the container search field.

ccf9769c22b844ff9b8d57417683b****

TargetType

string

No

The target type for container search. Valid values:

  • containerId: container ID

  • uuid: server UUID

  • imageUuid: image UUID

containerId

TacticId

string

No

The ATT&CK tactic ID.

TA0001

OperateErrorCodeList

array

No

The collection of alert event handling result codes.

string

No

The alert event handling result code. The format is: operation type.operation result code. The following operation types are supported:

  • Common: common operation

  • deal: handle

  • ignore: ignore

  • offline_handled: alert confirmed

  • mark_mis_info: add to whitelist

  • rm_mark_mis_info: remove from whitelist

  • quara: quarantine

  • kill_and_quara: standard scan and quarantine

  • kill_virus: deep cleanup

  • block_ip: block

  • manual_handled: manual handling

  • advance_mark_mis_info: add to precise defense whitelist

  • advance_mark_mis_info.System: automatically add to precise defense whitelist

  • advance_mark_mis_info.User: manually add to precise defense whitelist

Operation result codes:

  • Success: Succeeded.

  • Failure: Failed.

  • AgentOffline: Agent offline.

ignore. Success

OperateTimeStart

string

No

The start timestamp of the handling time.

2022-07-05 13:50:38

OperateTimeEnd

string

No

The end timestamp of the handling time.

2022-07-06 13:50:38

TimeStart

string

No

The start time of the latest occurrence. Format: YYYY-MM-DD HH:mm:ss.

2022-07-05 13:50:38

TimeEnd

string

No

The end time of the latest occurrence. Format: YYYY-MM-DD HH:mm:ss.

2022-07-06 13:50:38

SortColumn

string

No

The custom sort field. Default value: operateTime. Valid values:

  • lastTime: Latest occurrence time.

  • operateTime: Handling time.

Note

This field takes effect only when Dealed is set to Y.

operateTime

SortType

string

No

The custom sort order. Default value: desc. Valid values:

  • asc: Ascending order.

  • desc: Descending order.

Note

This field takes effect only when Dealed is set to Y.

desc

AssetsTypeList

array

No

The collection of asset types.

string

No

The asset type. Valid values:

  • ECS: Elastic Compute Service (ECS) instance.

  • CONTAINER: Container.

  • K8S: Kubernetes cluster.

ECS

ResourceDirectoryAccountId

integer

No

The Alibaba Cloud account ID of the member accounts in the resource directory.

Note

Call the DescribeMonitorAccounts operation to obtain this parameter.

16670360956*****

StrictMode

string

No

Specifies whether the alert is in strict mode. Valid values:

  • N: No.

  • Y: Yes.

Y

MultiAccountActionType

integer

No

The multi-account query type. Default value: 0. Valid values:

  • 0: Query data of the current account.

  • 1: Query data of all accounts.

0

SourceAliUids

array

No

The list of Alibaba Cloud account IDs that generated the alerts.

integer

No

The Alibaba Cloud account ID that generated the alert.

196072141348****

SupportOperateCodeList

array

No

The list of operation types supported by the alert.

string

No

The operation type supported by the alert. Valid values:

  • AI.false_positive: Suspected false positive.

  • AI.real_attack: Real attack.

  • AI.Insufficient_information_to_evaluate: Unable to determine.

AI.real_attack

DetectSource

string

No

The discovery source. This is an invalid field.

linux

Response elements

Element

Type

Description

Example

object

The response data of security alerts.

Count

integer

The number of entries returned on the current page in a paged query.

20

CurrentPage

integer

The page number of the current page in a paged query.

1

PageSize

integer

The maximum number of entries per page in a paged query.

20

RequestId

string

The ID of the request.

0D6E20E4-8326-1D03-A553-2182BE9E82F9

SuspEvents

array<object>

The security alert information.

array<object>

Advanced

boolean

Indicates whether the alert is from offline analysis.

true

AlarmEventName

string

The name of the alert event.

login_common_location

AlarmEventNameDisplay

string

The display name of the alert.

Login with unusual location

AlarmEventType

string

The alerting event type.

Unusual Logon

AlarmEventTypeDisplay

string

The alerting event type.

Unusual Logon

AlarmUniqueInfo

string

The unique ID of the alert event.

8df914418f****

AppName

string

The name of the application to which the alert event belongs.

pro-deploy-tibasic

AutoBreaking

boolean

Indicates whether automatic defense is enabled.

true

CanBeDealOnLine

boolean

Indicates whether the alert event can be handled online, such as quarantine. Valid values:

  • true: Online handling is supported.

  • false: Online handling is not supported.

true

CanCancelFault

boolean

Indicates whether the false positive marking can be unmarked. Valid values:

  • true: Can be unmarked.

  • false: Cannot be unmarked.

false

ContainHwMode

boolean

Indicates whether critical event protection mode is enabled for the server. Valid values:

  • true: Enabled.

  • false: Not enabled.

false

ContainerId

string

The container ID.

container_1648601865161_14925_02_000****

ContainerImageId

string

The container image ID.

sha256:2e5a3b0ae5f452b3cb458789a9a7542ef40035a84318469a8528c5e444db1****

ContainerImageName

string

The container image name.

centos7_apache:v1.0.1

DataSource

string

The data source. You can ignore this parameter.

aegis_suspicious_****

DeepAnalyzeReportUrl

string

The download URL of the deep file analysis report.

Note

Deep file analysis is triggered only for machines that have the AgenticEDR feature enabled.

Desc

string

The description of the impact of the alert event.

webshell

Details

array<object>

The details of the alert event.

object

The details of the anomalous event.

NameDisplay

string

The display name of the alert event.

Login with unusual location

Type

string

The alerting event type.

text

Value

string

The path where the alert event occurred.

/etc/crontab

ValueDisplay

string

The path where the alert event occurred.

/etc/crontab

DetectSource

string

The discovery source. This is an invalid field.

linux

DisplaySandboxResult

boolean

Indicates whether cloud sandbox detection is supported. Valid values:

  • true: Supported.

  • false: Not supported.

true

EventNotes

array<object>

The notes of the alert event.

object

Note

string

The note information.

Test

NoteId

integer

The event record ID.

123

NoteTime

string

The event record time. Format: YYYY-MM-DD HH:mm:ss.

2018-09-26 01:51:01

EventStatus

integer

The status of the alert event. Valid values:

  • 1: PENDING.

  • 2: IGNORE (ignored).

  • 4: HANDLED (confirmed).

  • 8: FAULT (marked as false positive).

  • 16: DEALING (being handled).

  • 32: DONE (handling completed).

  • 64: EXPIRE (expired).

  • 604: SYSTEM_FAULT (marked as false positive by the system).

8

EventSubType

string

The subtype of the alert event.

login_common_location

HasTraceInfo

boolean

Indicates whether the alert event has tracing information. Valid values:

  • true: Has tracing information.

  • false: Does not have tracing information.

true

Id

integer

The unique ID of the alert event.

1000

ImageUuid

string

The UUID of the image.

70489fb520cea585ad9761d5a842****

InstanceId

string

The ID of the asset instance affected by the alert event.

i-9dp6dwsxdl9z5u1e2f****

InstanceName

string

The name of the associated instance.

nginx

InternetIp

string

The public IP address of the associated instance.

1.2.XX.XX

IntranetIp

string

The private IP address of the associated instance.

100.100.XX.XX

K8sClusterId

string

The ID of the Kubernetes cluster.

c517b37e1401e4961b3951863a49a****

K8sClusterName

string

The name of the Kubernetes cluster.

test-daily

K8sNamespace

string

The Kubernetes namespace.

default

K8sNodeId

string

The ID of the Kubernetes node.

i-bp14a1ay8e0aa9t0****

K8sNodeName

string

The name of the Kubernetes node.

N/A

K8sPodName

string

The name of the Kubernetes pod.

myapp-pod

LargeModel

boolean

Indicates whether large model analysis tagging is supported. Valid values:

  • true: Supported.

  • false: Not supported.

true

LastTime

string

The most recent time when the alert event occurred. Format: YYYY-MM-DD HH:mm:ss.

2018-09-26 01:51:01

LastTimeStamp

integer

The timestamp of the last occurrence, in milliseconds.

1631699497000

Level

string

The severity level of the alert event. Valid values:

  • serious: Critical.

  • suspicious: Suspicious.

  • remind: Reminder.

serious

MaliciousRuleStatus

string

The status of the malicious behavior defense rule. Valid values:

  • open: Enabled.

  • close: Disabled.

open

MarkList

array

The collection of alert event tags.

string

The alert event tag.

mark

MarkMisRules

string

The advanced whitelisting rules.

1. &nbsppath &nbspcontain &nbsp232  

Name

string

The full name of the alert event.

Unusual Logon-Login with unusual location

OccurrenceTime

string

The time when the alert event first occurred. Format: YYYY-MM-DD HH:mm:ss.

2018-09-26 01:51:01

OccurrenceTimeStamp

integer

The timestamp of the first occurrence, in milliseconds.

1631699497000

OperateErrorCode

string

The error code of the alert event operation.

kill_and_quara.Success

OperateMsg

string

The remarks of the alert event operation.

success

OperateTime

integer

The timestamp of the alert event operation, in milliseconds.

1631699497000

SaleVersion

string

The product edition that supports the alert event detection. Valid values:

  • 0: Basic edition.

  • 1: Enterprise edition.

1

SecurityEventIds

string

The IDs of the alert events associated with this alert event.

270789

SourceAliUid

integer

The Alibaba Cloud account ID that generated the alert.

196072141348****

Stages

string

The attack stages.

"["authority_maintenance"]"

SupportOperateCode

string

The operation type supported by the alert. Valid values:

  • AI.false_positive: Suspected false positive.

  • AI.real_attack: Real attack.

  • AI.Insufficient_information_to_evaluate: Unable to determine.

AI.real_attack

TacticItems

array<object>

The display names of the attack stages.

object

TacticDisplayName

string

The ATT&CK tactic name.

Malicious scripts-Malicious script code execution

TacticId

string

The ATT&CK attack stage information.

TA0001

UniqueInfo

string

The unique key of the security alert.

e17e****

Uuid

string

The unique identifier of the associated instance.

bf6b30d3-eea8-4924-9f0a-****

clusterId

string

The cluster ID.

c2051775877374cccbf68af596e6****

TotalCount

integer

The total number of alert events.

100

Examples

Success response

JSON format

{
  "Count": 20,
  "CurrentPage": 1,
  "PageSize": 20,
  "RequestId": "0D6E20E4-8326-1D03-A553-2182BE9E82F9",
  "SuspEvents": [
    {
      "Advanced": true,
      "AlarmEventName": "login_common_location",
      "AlarmEventNameDisplay": "Login with unusual location",
      "AlarmEventType": "Unusual Logon",
      "AlarmEventTypeDisplay": "Unusual Logon",
      "AlarmUniqueInfo": "8df914418f****",
      "AppName": "pro-deploy-tibasic",
      "AutoBreaking": true,
      "CanBeDealOnLine": true,
      "CanCancelFault": false,
      "ContainHwMode": false,
      "ContainerId": "container_1648601865161_14925_02_000****",
      "ContainerImageId": "sha256:2e5a3b0ae5f452b3cb458789a9a7542ef40035a84318469a8528c5e444db1****",
      "ContainerImageName": "centos7_apache:v1.0.1",
      "DataSource": "aegis_suspicious_****",
      "DeepAnalyzeReportUrl": "",
      "Desc": "webshell",
      "Details": [
        {
          "NameDisplay": "Login with unusual location",
          "Type": "text",
          "Value": "/etc/crontab",
          "ValueDisplay": "/etc/crontab"
        }
      ],
      "DetectSource": "linux",
      "DisplaySandboxResult": true,
      "EventNotes": [
        {
          "Note": "Test",
          "NoteId": 123,
          "NoteTime": "2018-09-26 01:51:01\n"
        }
      ],
      "EventStatus": 8,
      "EventSubType": "login_common_location",
      "HasTraceInfo": true,
      "Id": 1000,
      "ImageUuid": "70489fb520cea585ad9761d5a842****",
      "InstanceId": "i-9dp6dwsxdl9z5u1e2f****",
      "InstanceName": "nginx",
      "InternetIp": "1.2.XX.XX",
      "IntranetIp": "100.100.XX.XX",
      "K8sClusterId": "c517b37e1401e4961b3951863a49a****",
      "K8sClusterName": "test-daily",
      "K8sNamespace": "default",
      "K8sNodeId": "i-bp14a1ay8e0aa9t0****\n",
      "K8sNodeName": "N/A",
      "K8sPodName": "myapp-pod\n",
      "LargeModel": true,
      "LastTime": "2018-09-26 01:51:01",
      "LastTimeStamp": 1631699497000,
      "Level": "serious",
      "MaliciousRuleStatus": "open",
      "MarkList": [
        "mark"
      ],
      "MarkMisRules": "1. &nbsppath &nbspcontain &nbsp232  ",
      "Name": "Unusual Logon-Login with unusual location",
      "OccurrenceTime": "2018-09-26 01:51:01",
      "OccurrenceTimeStamp": 1631699497000,
      "OperateErrorCode": "kill_and_quara.Success",
      "OperateMsg": "success",
      "OperateTime": 1631699497000,
      "SaleVersion": "1",
      "SecurityEventIds": "270789",
      "SourceAliUid": 0,
      "Stages": "\"[\"authority_maintenance\"]\"",
      "SupportOperateCode": "AI.real_attack",
      "TacticItems": [
        {
          "TacticDisplayName": "Malicious scripts-Malicious script code execution",
          "TacticId": "TA0001"
        }
      ],
      "UniqueInfo": "e17e****",
      "Uuid": "bf6b30d3-eea8-4924-9f0a-****",
      "clusterId": "c2051775877374cccbf68af596e6****"
    }
  ],
  "TotalCount": 100
}

Error codes

HTTP status code

Error code

Error message

Description

400 NoPermission no permission
400 UnknownError UnknownError
400 RdCheckNoPermission Resource directory account verification has no permission.
500 RdCheckInnerError Resource directory account service internal error.
500 ServerError ServerError
403 NoPermission caller has no permission You are not authorized to do this operation.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.