All Products
Search
Document Center

Security Center:ListCheckItemWarningMachine

Last Updated:Aug 28, 2026

Queries the machines that triggered warnings for a specified baseline check item.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

No authorization for this operation. If you encounter issues with this operation, contact technical support.

Request parameters

Parameter

Type

Required

Description

Example

CheckId

integer

Yes

The ID of the check item.

8

RiskType

string

No

The type of the check item.

cis

Status

integer

No

The status of the check item. Valid values:

  • 1: failed

  • 2: verifying

  • 3: passed

  • 6: ignored

  • 7: fixing

  • 8: fixed

3

Remark

string

No

The keyword for fuzzy-match server queries.

225

ContainerFieldName

string

No

The field name for querying containers.

clusterId

ContainerFieldValue

string

No

The field value for querying containers.

ce89cdd0ea732472a8703821b19e****

Lang

string

No

The language of the content within the request and response. Default value: zh. Valid values:

  • zh: Chinese

  • en: English

zh

CurrentPage

integer

No

The page number to return. Pages start from page 1. Default value: 1.

1

PageSize

integer

No

The number of entries per page. Default value: 20.

Note

We recommend that you do not leave this parameter empty.

20

GroupId

integer

No

The ID of the asset group.

Note

You can call the DescribeAllGroups operation to query the ID of the asset group.

1161****

Source

string

No

The data source. Default value: default. Valid values:

  • default: The check items of baselines for hosts.

  • agentless: The check items of baselines for agentless detection.

agentless

UuidList

array

No

The UUID array of the servers.

string

No

The UUID of the servers.

Note

You can call the DescribeCloudCenterInstances operation to query the UUIDs of servers.

4fe8e1cd-3c37-4851-b9de-124da32c****

ResourceDirectoryAccountId

integer

No

The Alibaba Cloud account ID of the member in the resource directory.

Note

You can call the DescribeMonitorAccounts operation to obtain the IDs.

1082098404740323

Response elements

Element

Type

Description

Example

object

The paginated list of servers that generated alerts.

List

array<object>

The servers that generated alerts.

array<object>

The server that generated the alert.

Status

integer

The status of the check item. Valid values:

  • 1: failed

  • 2: verifying

  • 3: passed

  • 6: ignored

  • 7: fixing

  • 8: fixed

1

Bind

boolean

Indicates whether Security Center is authorized to protect the asset. Valid values:

  • true

  • false

true

AuthVersion

integer

The edition of Security Center that is authorized to protect the asset. Valid values:

  • 1: Basic edition

  • 6: Anti-virus edition

  • 5: Advanced edition

  • 3: Enterprise edition

  • 7: Ultimate edition

  • 10: Value-added Plan edition

3

PortOpen

boolean

Indicates whether a port on the server is accessible over the Internet. Valid values:

  • true

  • false

true

InstanceId

string

The instance ID of the server.

i-bp1a69mvjujbakxu****

IntranetIp

string

The private IP address of the affected asset.

172.25.XX.XX

InternetIp

string

The public IP address of the affected asset.

8.210.XX.XX

InstanceName

string

The name of the server.

sql-test-0****

Uuid

string

The UUID of the server.

49e25e0f-bb51-4a5a-a1b3-13a4ddaa****

RegionId

string

The region ID of the asset.

cn-hangzhou

Prompt

string

The prompt for the risk item.

There is a weak password (username/password): root/he*****34

WarningRiskList deprecated

array<object>

The baselines on which the risk item was detected.

object

The baseline on which the risk item was detected.

RiskId deprecated

integer

The ID of the baseline.

72

RiskName deprecated

string

The name of the baseline.

Alibaba Cloud Linux/Aliyun Linux 2 Baseline for China classified protection of cybersecurity-Level II

FixList

array<object>

The baselines for which the risk item can be fixed.

object

The baseline for which the risk item can be fixed.

RiskId

integer

The ID of the baseline.

72

RiskName

string

The name of the baseline.

Alibaba Cloud Linux/Aliyun Linux 2 Baseline for China classified protection of cybersecurity-Level II

ContainerId

string

The ID of the container.

48a6d9a92435a13ad573372c3f3c63b7e04d106458141df9f9215570********

ContainerName

string

The name of the container.

step-build-ui-build

TargetName

string

The name of the asset where the malicious image sample was detected.

jenkins****

TargetId

string

The ID of the scanned asset.

30****

TargetType

string

The type of the asset. Valid values:

  • ECS_SNAPSHOT

  • ECS_IMAGE

ECS_IMAGE

LastScanTime

integer

The timestamp of the last scan. Unit: milliseconds.

1694692471000

LastHandleTime

integer

The timestamp when the check item risk was last handled on the machine. Unit: milliseconds.

1694692471000

FixStatus

integer

Indicates whether the fix is supported. Valid values:

  • 0: Supported

  • 1: Not Supported

1

AssetType

string

The type of the cloud product asset.

0

PageInfo

object

The pagination information.

CurrentPage

integer

The page number.

1

PageSize

integer

The number of entries returned per page.

20

TotalCount

integer

The total number of affected assets.

107

Count

integer

The number of affected assets returned on the current page.

4

RequestId

string

The request ID.

22B5615F-700E-575A-A6D5-DC8D7741****

Examples

Success response

JSON format

{
  "List": [
    {
      "Status": 1,
      "Bind": true,
      "AuthVersion": 3,
      "PortOpen": true,
      "InstanceId": "i-bp1a69mvjujbakxu****",
      "IntranetIp": "172.25.XX.XX",
      "InternetIp": "8.210.XX.XX",
      "InstanceName": "sql-test-0****",
      "Uuid": "49e25e0f-bb51-4a5a-a1b3-13a4ddaa****",
      "RegionId": "cn-hangzhou",
      "Prompt": "There is a weak password (username/password): root/he*****34",
      "WarningRiskList": [
        {
          "RiskId": 72,
          "RiskName": "Alibaba Cloud Linux/Aliyun Linux 2 Baseline for China classified protection of cybersecurity-Level II"
        }
      ],
      "FixList": [
        {
          "RiskId": 72,
          "RiskName": "Alibaba Cloud Linux/Aliyun Linux 2 Baseline for China classified protection of cybersecurity-Level II"
        }
      ],
      "ContainerId": "48a6d9a92435a13ad573372c3f3c63b7e04d106458141df9f9215570********",
      "ContainerName": "step-build-ui-build",
      "TargetName": "jenkins****",
      "TargetId": "30****",
      "TargetType": "ECS_IMAGE",
      "LastScanTime": 1694692471000,
      "LastHandleTime": 1694692471000,
      "FixStatus": 1,
      "AssetType": "0"
    }
  ],
  "PageInfo": {
    "CurrentPage": 1,
    "PageSize": 20,
    "TotalCount": 107,
    "Count": 4
  },
  "RequestId": "22B5615F-700E-575A-A6D5-DC8D7741****"
}

Error codes

HTTP status code

Error code

Error message

Description

400 RdCheckNoPermission Resource directory account verification has no permission.
500 ServerError ServerError
500 RdCheckInnerError Resource directory account service internal error.
403 NoPermission caller has no permission You are not authorized to do this operation.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.