Queries a list of security alert events that have not been aggregated.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:DescribeSuspEvents |
get |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| SourceIp |
string |
No |
The IP address of the access source. |
192.168.XX.XX |
| Dealed |
string |
No |
Specifies whether the alert events to query have been handled. Valid values:
|
N |
| Name |
string |
No |
The name of the asset affected by the alert event. |
ecs-xxx |
| Levels |
string |
No |
The severity levels of the alert events to query. Separate multiple severity levels with commas (,). The severity levels are listed in descending order. Valid values:
|
serious |
| ParentEventTypes |
string |
No |
The alerting type of the alert events to query. Valid values:
|
other |
| EventNames |
string |
No |
The subtypes of the alert events. Separate multiple subtypes with commas (,). |
WEBSHELL |
| Remark |
string |
No |
The alert name or asset information to query. Note
Fuzzy match is supported. Asset information includes the asset name, public IP address, and private IP address. |
192.168.XX.XX |
| Status |
string |
No |
The status of the alert events to query. Valid values:
|
1 |
| PageSize |
string |
No |
The number of alert events to display on each page in a paged query. Default value: 20, which indicates that 20 alert events are displayed on each page. Maximum value: 100. |
20 |
| CurrentPage |
string |
No |
The page number of the page to return in a paged query. Default value: 1, which indicates that the results start from page 1. |
1 |
| Lang |
string |
No |
The language of the request and response. Default value: zh. Valid values:
|
zh |
| AlarmUniqueInfo |
string |
No |
The unique ID of the alert event. Note
To query the exception information of a single alert event, provide the unique ID of the alert event. You can obtain this ID by calling the DescribeSuspEvents operation. |
8df914418f4211fb**** |
| UniqueInfo |
string |
No |
The unique key of the security alert. |
73fc06fb175a7405697e402f52864**** |
| Id |
integer |
No |
The unique ID that identifies the alert event record. |
123 |
| From |
string |
No |
The data source identifier of the alert event. The value is fixed as sas. |
sas |
| Source |
string |
No |
The alert source. |
aegis_suspicious_file_v2 |
| GroupId |
integer |
No |
The group ID of the asset affected by the alert event. |
18768 |
| Uuids |
string |
No |
The UUIDs of the servers for which you want to query alerts. Separate multiple UUIDs with commas (,). |
bb5d2484-f10e-450d-8917-3e79667e****,0e7c2fcd-7100-42c7-a21a-db6e4f32**** |
| ClusterId |
string |
No |
The cluster ID for which you want to query alert events. |
c4af4fdf38a98496a9b63c2be5dae**** |
| ContainerFieldName |
string |
No |
The container search field. Valid values:
|
instanceId |
| ContainerFieldValue |
string |
No |
The value of the container search field. |
ccf9769c22b844ff9b8d57417683b**** |
| TargetType |
string |
No |
The target type for container search. Valid values:
|
containerId |
| TacticId |
string |
No |
The ATT&CK tactic ID. |
TA0001 |
| OperateErrorCodeList |
array |
No |
The collection of alert event handling result codes. |
|
|
string |
No |
The alert event handling result code. The format is: operation type.operation result code. The following operation types are supported:
Operation result codes:
|
ignore. Success |
|
| OperateTimeStart |
string |
No |
The start timestamp of the handling time. |
2022-07-05 13:50:38 |
| OperateTimeEnd |
string |
No |
The end timestamp of the handling time. |
2022-07-06 13:50:38 |
| TimeStart |
string |
No |
The start time of the latest occurrence. Format: YYYY-MM-DD HH:mm:ss. |
2022-07-05 13:50:38 |
| TimeEnd |
string |
No |
The end time of the latest occurrence. Format: YYYY-MM-DD HH:mm:ss. |
2022-07-06 13:50:38 |
| SortColumn |
string |
No |
The custom sort field. Default value: operateTime. Valid values:
Note
This field takes effect only when Dealed is set to Y. |
operateTime |
| SortType |
string |
No |
The custom sort order. Default value: desc. Valid values:
Note
This field takes effect only when Dealed is set to Y. |
desc |
| AssetsTypeList |
array |
No |
The collection of asset types. |
|
|
string |
No |
The asset type. Valid values:
|
ECS |
|
| ResourceDirectoryAccountId |
integer |
No |
The Alibaba Cloud account ID of the member accounts in the resource directory. Note
Call the DescribeMonitorAccounts operation to obtain this parameter. |
16670360956***** |
| StrictMode |
string |
No |
Specifies whether the alert is in strict mode. Valid values:
|
Y |
| MultiAccountActionType |
integer |
No |
The multi-account query type. Default value: 0. Valid values:
|
0 |
| SourceAliUids |
array |
No |
The list of Alibaba Cloud account IDs that generated the alerts. |
|
|
integer |
No |
The Alibaba Cloud account ID that generated the alert. |
196072141348**** |
|
| SupportOperateCodeList |
array |
No |
The list of operation types supported by the alert. |
|
|
string |
No |
The operation type supported by the alert. Valid values:
|
AI.real_attack |
|
| DetectSource |
string |
No |
The discovery source. This is an invalid field. |
linux |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response data of security alerts. |
||
| Count |
integer |
The number of entries returned on the current page in a paged query. |
20 |
| CurrentPage |
integer |
The page number of the current page in a paged query. |
1 |
| PageSize |
integer |
The maximum number of entries per page in a paged query. |
20 |
| RequestId |
string |
The ID of the request. |
0D6E20E4-8326-1D03-A553-2182BE9E82F9 |
| SuspEvents |
array<object> |
The security alert information. |
|
|
array<object> |
|||
| Advanced |
boolean |
Indicates whether the alert is from offline analysis. |
true |
| AlarmEventName |
string |
The name of the alert event. |
login_common_location |
| AlarmEventNameDisplay |
string |
The display name of the alert. |
Login with unusual location |
| AlarmEventType |
string |
The alerting event type. |
Unusual Logon |
| AlarmEventTypeDisplay |
string |
The alerting event type. |
Unusual Logon |
| AlarmUniqueInfo |
string |
The unique ID of the alert event. |
8df914418f**** |
| AppName |
string |
The name of the application to which the alert event belongs. |
pro-deploy-tibasic |
| AutoBreaking |
boolean |
Indicates whether automatic defense is enabled. |
true |
| CanBeDealOnLine |
boolean |
Indicates whether the alert event can be handled online, such as quarantine. Valid values:
|
true |
| CanCancelFault |
boolean |
Indicates whether the false positive marking can be unmarked. Valid values:
|
false |
| ContainHwMode |
boolean |
Indicates whether critical event protection mode is enabled for the server. Valid values:
|
false |
| ContainerId |
string |
The container ID. |
container_1648601865161_14925_02_000**** |
| ContainerImageId |
string |
The container image ID. |
sha256:2e5a3b0ae5f452b3cb458789a9a7542ef40035a84318469a8528c5e444db1**** |
| ContainerImageName |
string |
The container image name. |
centos7_apache:v1.0.1 |
| DataSource |
string |
The data source. You can ignore this parameter. |
aegis_suspicious_**** |
| DeepAnalyzeReportUrl |
string |
The download URL of the deep file analysis report. Note
Deep file analysis is triggered only for machines that have the AgenticEDR feature enabled. |
|
| Desc |
string |
The description of the impact of the alert event. |
webshell |
| Details |
array<object> |
The details of the alert event. |
|
|
object |
The details of the anomalous event. |
||
| NameDisplay |
string |
The display name of the alert event. |
Login with unusual location |
| Type |
string |
The alerting event type. |
text |
| Value |
string |
The path where the alert event occurred. |
/etc/crontab |
| ValueDisplay |
string |
The path where the alert event occurred. |
/etc/crontab |
| DetectSource |
string |
The discovery source. This is an invalid field. |
linux |
| DisplaySandboxResult |
boolean |
Indicates whether cloud sandbox detection is supported. Valid values:
|
true |
| EventNotes |
array<object> |
The notes of the alert event. |
|
|
object |
|||
| Note |
string |
The note information. |
Test |
| NoteId |
integer |
The event record ID. |
123 |
| NoteTime |
string |
The event record time. Format: YYYY-MM-DD HH:mm:ss. |
2018-09-26 01:51:01 |
| EventStatus |
integer |
The status of the alert event. Valid values:
|
8 |
| EventSubType |
string |
The subtype of the alert event. |
login_common_location |
| HasTraceInfo |
boolean |
Indicates whether the alert event has tracing information. Valid values:
|
true |
| Id |
integer |
The unique ID of the alert event. |
1000 |
| ImageUuid |
string |
The UUID of the image. |
70489fb520cea585ad9761d5a842**** |
| InstanceId |
string |
The ID of the asset instance affected by the alert event. |
i-9dp6dwsxdl9z5u1e2f**** |
| InstanceName |
string |
The name of the associated instance. |
nginx |
| InternetIp |
string |
The public IP address of the associated instance. |
1.2.XX.XX |
| IntranetIp |
string |
The private IP address of the associated instance. |
100.100.XX.XX |
| K8sClusterId |
string |
The ID of the Kubernetes cluster. |
c517b37e1401e4961b3951863a49a**** |
| K8sClusterName |
string |
The name of the Kubernetes cluster. |
test-daily |
| K8sNamespace |
string |
The Kubernetes namespace. |
default |
| K8sNodeId |
string |
The ID of the Kubernetes node. |
i-bp14a1ay8e0aa9t0**** |
| K8sNodeName |
string |
The name of the Kubernetes node. |
N/A |
| K8sPodName |
string |
The name of the Kubernetes pod. |
myapp-pod |
| LargeModel |
boolean |
Indicates whether large model analysis tagging is supported. Valid values:
|
true |
| LastTime |
string |
The most recent time when the alert event occurred. Format: YYYY-MM-DD HH:mm:ss. |
2018-09-26 01:51:01 |
| LastTimeStamp |
integer |
The timestamp of the last occurrence, in milliseconds. |
1631699497000 |
| Level |
string |
The severity level of the alert event. Valid values:
|
serious |
| MaliciousRuleStatus |
string |
The status of the malicious behavior defense rule. Valid values:
|
open |
| MarkList |
array |
The collection of alert event tags. |
|
|
string |
The alert event tag. |
mark |
|
| MarkMisRules |
string |
The advanced whitelisting rules. |
1.  path  contain  232 |
| Name |
string |
The full name of the alert event. |
Unusual Logon-Login with unusual location |
| OccurrenceTime |
string |
The time when the alert event first occurred. Format: YYYY-MM-DD HH:mm:ss. |
2018-09-26 01:51:01 |
| OccurrenceTimeStamp |
integer |
The timestamp of the first occurrence, in milliseconds. |
1631699497000 |
| OperateErrorCode |
string |
The error code of the alert event operation. |
kill_and_quara.Success |
| OperateMsg |
string |
The remarks of the alert event operation. |
success |
| OperateTime |
integer |
The timestamp of the alert event operation, in milliseconds. |
1631699497000 |
| SaleVersion |
string |
The product edition that supports the alert event detection. Valid values:
|
1 |
| SecurityEventIds |
string |
The IDs of the alert events associated with this alert event. |
270789 |
| SourceAliUid |
integer |
The Alibaba Cloud account ID that generated the alert. |
196072141348**** |
| Stages |
string |
The attack stages. |
"["authority_maintenance"]" |
| SupportOperateCode |
string |
The operation type supported by the alert. Valid values:
|
AI.real_attack |
| TacticItems |
array<object> |
The display names of the attack stages. |
|
|
object |
|||
| TacticDisplayName |
string |
The ATT&CK tactic name. |
Malicious scripts-Malicious script code execution |
| TacticId |
string |
The ATT&CK attack stage information. |
TA0001 |
| UniqueInfo |
string |
The unique key of the security alert. |
e17e**** |
| Uuid |
string |
The unique identifier of the associated instance. |
bf6b30d3-eea8-4924-9f0a-**** |
| clusterId |
string |
The cluster ID. |
c2051775877374cccbf68af596e6**** |
| TotalCount |
integer |
The total number of alert events. |
100 |
Examples
Success response
JSON format
{
"Count": 20,
"CurrentPage": 1,
"PageSize": 20,
"RequestId": "0D6E20E4-8326-1D03-A553-2182BE9E82F9",
"SuspEvents": [
{
"Advanced": true,
"AlarmEventName": "login_common_location",
"AlarmEventNameDisplay": "Login with unusual location",
"AlarmEventType": "Unusual Logon",
"AlarmEventTypeDisplay": "Unusual Logon",
"AlarmUniqueInfo": "8df914418f****",
"AppName": "pro-deploy-tibasic",
"AutoBreaking": true,
"CanBeDealOnLine": true,
"CanCancelFault": false,
"ContainHwMode": false,
"ContainerId": "container_1648601865161_14925_02_000****",
"ContainerImageId": "sha256:2e5a3b0ae5f452b3cb458789a9a7542ef40035a84318469a8528c5e444db1****",
"ContainerImageName": "centos7_apache:v1.0.1",
"DataSource": "aegis_suspicious_****",
"DeepAnalyzeReportUrl": "",
"Desc": "webshell",
"Details": [
{
"NameDisplay": "Login with unusual location",
"Type": "text",
"Value": "/etc/crontab",
"ValueDisplay": "/etc/crontab"
}
],
"DetectSource": "linux",
"DisplaySandboxResult": true,
"EventNotes": [
{
"Note": "Test",
"NoteId": 123,
"NoteTime": "2018-09-26 01:51:01\n"
}
],
"EventStatus": 8,
"EventSubType": "login_common_location",
"HasTraceInfo": true,
"Id": 1000,
"ImageUuid": "70489fb520cea585ad9761d5a842****",
"InstanceId": "i-9dp6dwsxdl9z5u1e2f****",
"InstanceName": "nginx",
"InternetIp": "1.2.XX.XX",
"IntranetIp": "100.100.XX.XX",
"K8sClusterId": "c517b37e1401e4961b3951863a49a****",
"K8sClusterName": "test-daily",
"K8sNamespace": "default",
"K8sNodeId": "i-bp14a1ay8e0aa9t0****\n",
"K8sNodeName": "N/A",
"K8sPodName": "myapp-pod\n",
"LargeModel": true,
"LastTime": "2018-09-26 01:51:01",
"LastTimeStamp": 1631699497000,
"Level": "serious",
"MaliciousRuleStatus": "open",
"MarkList": [
"mark"
],
"MarkMisRules": "1.  path  contain  232 ",
"Name": "Unusual Logon-Login with unusual location",
"OccurrenceTime": "2018-09-26 01:51:01",
"OccurrenceTimeStamp": 1631699497000,
"OperateErrorCode": "kill_and_quara.Success",
"OperateMsg": "success",
"OperateTime": 1631699497000,
"SaleVersion": "1",
"SecurityEventIds": "270789",
"SourceAliUid": 0,
"Stages": "\"[\"authority_maintenance\"]\"",
"SupportOperateCode": "AI.real_attack",
"TacticItems": [
{
"TacticDisplayName": "Malicious scripts-Malicious script code execution",
"TacticId": "TA0001"
}
],
"UniqueInfo": "e17e****",
"Uuid": "bf6b30d3-eea8-4924-9f0a-****",
"clusterId": "c2051775877374cccbf68af596e6****"
}
],
"TotalCount": 100
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | NoPermission | no permission | |
| 400 | UnknownError | UnknownError | |
| 400 | RdCheckNoPermission | Resource directory account verification has no permission. | |
| 500 | RdCheckInnerError | Resource directory account service internal error. | |
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission | You are not authorized to do this operation. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.