Handles security alert events by performing operations such as blocking IP addresses, terminating malicious processes, or adding events to the whitelist.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:HandleSecurityEvents |
none |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| SourceIp |
string |
No |
The source IP address of the request. |
1.2.XX.XX |
| OperationCode |
string |
Yes |
The operation to perform on the alert events. Valid values:
|
block_ip |
| OperationParams |
string |
No |
The configuration of the handling operation. Note
If you set OperationCode to |
{\"expireTime\":1719588943551,\"subOperation\":\"killAndQuaraFileByMd5andPath\"} |
| MarkMissParam |
string |
No |
The whitelist rule in JSON format. Contains the following fields:
Note
You can call the DescribeSecurityEventOperations operation to obtain the fields that you can specify for field. |
[{"uuid":"part","field":"gmtModified","operate":"contains","fieldValue":"asd"},{"uuid":"part","field":"loginUser","operate":"contains","fieldValue":"vff"}] |
| MarkBatch |
string |
No |
Whether to add multiple alert events to the whitelist at a time. Valid values:
|
true |
| SecurityEventIds |
array |
Yes |
The IDs of the alert events. |
["909361"] |
|
string |
Yes |
The ID of the alert event. |
909361 |
|
| Remark |
string |
No |
Remarks for the handling operation. |
remark test. |
| ResourceDirectoryAccountId |
integer |
No |
The Alibaba Cloud account ID of the member in the resource directory. Note
You can call the DescribeMonitorAccounts operation to obtain the IDs. |
127608589417**** |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| RequestId |
string |
The request ID. |
FF0020B9-999F-5DE2-985F-DB282BDA5311 |
| HandleSecurityEventsResponse |
object |
The result of handling the alert events. |
|
| TaskId |
integer |
The ID of the alert handling task. |
15411 |
Examples
Success response
JSON format
{
"RequestId": "FF0020B9-999F-5DE2-985F-DB282BDA5311",
"HandleSecurityEventsResponse": {
"TaskId": 15411
}
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | NoPermission | no permission | |
| 400 | SecurityEventNotExists | Security event not exists. | |
| 400 | RdCheckNoPermission | Resource directory account verification has no permission. | |
| 500 | RdCheckInnerError | Resource directory account service internal error. | |
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission | You are not authorized to do this operation. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.