Handles alert events in batches.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:OperationSuspEvents |
none |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| SourceIp |
string |
No |
The IP address of the access source. |
1.2.XX.XX |
| SuspiciousEventIds |
string |
Yes |
The list of alert event IDs. Note
You can call DescribeSuspEvents to obtain alert event IDs from the SecurityEventIds response parameter. |
290852 |
| Operation |
string |
Yes |
The operation to perform on the alert. Valid values:
|
deal |
| SubOperation |
string |
No |
The sub-operation type to perform when quarantining the alert event. Valid values:
|
killAndQuaraFileByPidAndMd5andPath |
| From |
string |
No |
The request source identifier. Set this parameter to sas, which indicates a request from the Security Center client. |
sas |
| WarnType |
string |
No |
The type of the exception event to handle. Valid values:
|
alarm |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| Success |
boolean |
Indicates whether the alert events are handled. Valid values:
|
true |
| RequestId |
string |
The request ID, which is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot issues. |
7E0618A9-D5EF-4220-9471-C42B5E92719F |
| AccessCode |
string |
Indicates whether you have the access permission. Valid values:
|
pass |
Examples
Success response
JSON format
{
"Success": true,
"RequestId": "7E0618A9-D5EF-4220-9471-C42B5E92719F",
"AccessCode": "pass"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | ClientOffline | Client offline | |
| 400 | UnknownError | UnknownError | |
| 400 | IllegalParam | Illegal param | |
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.