Retrieves the details of a honeypot attack event.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:ListHoneypotEventFlows |
list |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| Dealed |
string |
No |
Specifies whether the event has been handled. Valid values:
|
n |
| SecurityEventId |
integer |
No |
The ID of the alert event. Note
You can call the ListHoneypotEvents operation to obtain this parameter. |
7455818 |
| CurrentPage |
integer |
No |
The page number of the current page in a paged query. Default value: 1. |
1 |
| PageSize |
integer |
No |
The maximum number of entries to return per page in a paged query. Default value: 100. If the PageSize parameter is left empty, 100 entries are returned by default. Note
Do not leave PageSize empty. |
20 |
| RequestId |
string |
No |
Invalid parameter. |
9F4E6157-9600-5588-86B9-38F09067**** |
| Lang |
string |
No |
The language of the request and response. Default value: zh. Valid values:
|
zh |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The paginated result data. |
||
| HoneypotEventFlows |
array<object> |
The list of attack timeline entries. |
|
|
object |
The attack timeline information. |
||
| SecurityEventId |
integer |
The unique ID of the attack event. |
306527555 |
| HoneypotEventId |
string |
The attack event ID in string format. |
19bec028-d98b-45c4-a4d9-cc3d593f**** |
| LastTime |
integer |
The most recent time when the attack event occurred, in UNIX timestamp format. |
1686622222000 |
| FirstTime |
integer |
The first time when the attack event occurred, in UNIX timestamp format. |
1686621122000 |
| EventConnection |
string |
The unique ID of the connection during the attack. |
fd7f1ff4-0c4b-41cb-99ad-0724349d**** |
| AgentId |
string |
The ID of the probe. |
d3c0dafa-5059-4eb0-8c28-7d40f58***** |
| AgentName |
string |
The name of the probe. |
hw-d*** |
| HoneypotId |
string |
The ID of the honeypot. |
911df9d6fe20451c059edbcffa1d1c33452f6a71e59d4826da067af224***** |
| HoneypotName |
string |
The name of the honeypot. |
hw-zhi***** |
| DockerId |
string |
The ID of the container. |
eca09895**** |
| DstIp |
string |
The destination IP address. |
112.126.205.*** |
| DstPort |
integer |
The destination port. |
80 |
| SrcIp |
string |
The attack source IP address. |
121.41.48.*** |
| SrcMac |
string |
The source MAC address of the attack. |
00:0C:29:CA:**:** |
| SrcPort |
integer |
The source port number. |
80 |
| TypeId |
string |
The ID of the attack type. |
web_access |
| RiskLevel |
string |
The risk level. Valid values:
|
4 |
| Extra |
string |
The extended information of the attack payload. |
{\"payload\":{\"format\":\"line\",\"name\":{\"cn\":\"\",\"en\":\"payload\"},\"value\":\"\"},\"uid\":{\"format\":\"line\",\"name\":{\"cn\":\"\",\"en\":\"\"},\"uid\":\"5fa2ece9-aa08-4bbd-a272-5d27*********\",\"value\":\"\"}} |
| Extra1 |
string |
The VPC extended information. |
{\"vpc_id\":\"\",\"vpc_dest_port\":\"\",\"vpc_dest_ip\":\"\"} |
| Uid |
string |
The unique ID of a single attack action within the attack event. |
5fa2ece9-aa08-4bbd-a272-5d27d1c6***** |
| Status |
integer |
The handling status of the attack event. Valid values:
|
1 |
| FileOssUrl |
string |
The OSS URL of the file. |
https://pop-test-file-upload.oss-cn-beijing.aliyuncs.com/5626_26331***** |
| PageInfo |
object |
The paging information for the query. |
|
| CurrentPage |
integer |
The page number of the current page in the paged query. |
1 |
| PageSize |
integer |
The maximum number of entries displayed per page in the paged query. |
20 |
| TotalCount |
integer |
The total number of entries. |
78 |
| Count |
integer |
The number of entries on the current page. |
20 |
| Success |
boolean |
Indicates whether the call was successful. Valid values:
|
true |
| Code |
string |
The result code. A value of 200 indicates success. Any other value indicates failure. You can use this field to determine the cause of the failure. |
200 |
| Message |
string |
The response message. |
successful |
| RequestId |
string |
The request ID, which is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot issues. |
9F4E6157-9600-5588-86B9-38F09067**** |
| HttpStatusCode |
integer |
The HTTP status code. |
200 |
Examples
Success response
JSON format
{
"HoneypotEventFlows": [
{
"SecurityEventId": 306527555,
"HoneypotEventId": "19bec028-d98b-45c4-a4d9-cc3d593f****",
"LastTime": 1686622222000,
"FirstTime": 1686621122000,
"EventConnection": "fd7f1ff4-0c4b-41cb-99ad-0724349d****",
"AgentId": "d3c0dafa-5059-4eb0-8c28-7d40f58*****",
"AgentName": "hw-d***",
"HoneypotId": "911df9d6fe20451c059edbcffa1d1c33452f6a71e59d4826da067af224*****",
"HoneypotName": "hw-zhi*****",
"DockerId": "eca09895****",
"DstIp": "112.126.205.***",
"DstPort": 80,
"SrcIp": "121.41.48.***",
"SrcMac": "00:0C:29:CA:**:**",
"SrcPort": 80,
"TypeId": "web_access",
"RiskLevel": "4",
"Extra": "{\\\"payload\\\":{\\\"format\\\":\\\"line\\\",\\\"name\\\":{\\\"cn\\\":\\\"\\\",\\\"en\\\":\\\"payload\\\"},\\\"value\\\":\\\"\\\"},\\\"uid\\\":{\\\"format\\\":\\\"line\\\",\\\"name\\\":{\\\"cn\\\":\\\"\\\",\\\"en\\\":\\\"\\\"},\\\"uid\\\":\\\"5fa2ece9-aa08-4bbd-a272-5d27*********\\\",\\\"value\\\":\\\"\\\"}}",
"Extra1": "{\\\"vpc_id\\\":\\\"\\\",\\\"vpc_dest_port\\\":\\\"\\\",\\\"vpc_dest_ip\\\":\\\"\\\"}",
"Uid": "5fa2ece9-aa08-4bbd-a272-5d27d1c6*****",
"Status": 1,
"FileOssUrl": "https://pop-test-file-upload.oss-cn-beijing.aliyuncs.com/5626_26331*****"
}
],
"PageInfo": {
"CurrentPage": 1,
"PageSize": 20,
"TotalCount": 78,
"Count": 20
},
"Success": true,
"Code": "200",
"Message": "successful",
"RequestId": "9F4E6157-9600-5588-86B9-38F09067****",
"HttpStatusCode": 200
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | IllegalParam | Illegal param | |
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.