Batch processes alert events based on the same IP rule or type.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:HandleSimilarSecurityEvents |
none |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| SourceIp |
string |
No |
The IP address of the access source. |
192.168.XX.XX |
| TaskId |
integer |
Yes |
The ID of the task that batch processes all alert events of the same type. Note
Call the CreateSimilarSecurityEventsQueryTask operation to obtain this parameter. |
666038 |
| OperationCode |
string |
Yes |
The type of operation for batch processing alert events of the same type. Note
Call the DescribeSecurityEventOperations operation to obtain this parameter. |
offline_handled |
| OperationParams |
string |
No |
The configuration of the sub-operation for handling alerting events. The value is in JSON format. Note
This parameter is required when OperationCode is set to kill_and_quara, block_ip, or virus_quara. For other values of OperationCode, this parameter can be left empty. Note
When OperationCode is set to block_ip, the following field is included:
When OperationCode is set to kill_and_quara, the following field is included:
When OperationCode is set to virus_quara, the following field is included:
|
{"expireTime":1646208726195} |
| MarkMissParam |
string |
No |
The rule for adding items to the whitelist. For example, to add a whitelist rule based on file MD5 where the file contains the string "a", set this parameter to {"field":"md5","operate":"contains","fieldValue":"aa"}. |
{"field":"md5","operate":"contains","fieldValue":"aa"} |
| Remark |
string |
No |
The remarks for the operation. |
remark test. |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| RequestId |
string |
The request ID, which is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot issues. |
A3653911-33A6-5268-8B91-7690471F7AA1 |
Examples
Success response
JSON format
{
"RequestId": "A3653911-33A6-5268-8B91-7690471F7AA1"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | DataRetrieveNotFinished | Data retrieving not finished yet | |
| 400 | IllegalParam | Illegal param | |
| 400 | OperationTaskNotExists | The specified operation task does not exist | |
| 400 | MissingTaskId | Task id is mandatory for this action. | |
| 400 | InvalidOperationForEvent | The operation is invalid for the event. | |
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.