Queries the details of an API security event.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-waf:DescribeApisecEventDetail |
get |
*All Resource
|
|
None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| InstanceId |
string |
Yes |
Instance ID of the WAF instance. Note
You can call the DescribeInstance operation to query instance ID of the WAF instance. |
waf_elasticity-cn-0xldbqtm005 |
| RegionId |
string |
No |
The region where the WAF instance is deployed. Valid values:
|
cn-hangzhou |
| ResourceManagerResourceGroupId |
string |
No |
The ID of the Alibaba Cloud resource group. |
rg-acfm***q |
| EventId |
string |
Yes |
The ID of the API security event. |
18ba94fea9***e66ba0557b7b91 |
| EventScope |
string |
No |
The dimension of the security event. Valid values:
|
ip |
| DetailType |
string |
No |
The type of detailed information about the security event. Valid values:
|
event_info |
| ClusterId |
string |
No |
The ID of the hybrid cloud cluster. Note
This parameter applies only to hybrid cloud scenarios. You can call the DescribeHybridCloudClusters operation to query hybrid cloud cluster information. |
428 |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| RequestId |
string |
The request ID. |
D7861F61-5B61-46CE-A47C-6B19160D5EB0 |
| EventId |
string |
The ID of the API security event. |
18ba94fea9***e66ba0557b7b91 |
| EventTag |
string |
The event type. Note
You can call the DescribeApisecRules operation to query the supported event types. |
ObtainSensitiveUnauthorized |
| AttackerList |
array |
The attacker list. |
|
|
string |
The attacker information. Note
If EventScope is set to ip, this value is the attacker IP address. If EventScope is set to account, this value is the attacker account. |
104.234.140.** |
|
| AttackCnt |
string |
The number of attacks. |
345 |
| StartTs |
string |
The start time of the query. The value is a UNIX timestamp (UTC). Unit: seconds. |
1683648000 |
| EndTs |
string |
The end time of the query. The value is a UNIX timestamp (UTC). Unit: seconds. |
1683703260 |
| Origin |
string |
The origin of the event type. Valid values:
|
custom |
| EventLevel |
string |
The event level. Valid values:
|
low |
| UserStatus |
string |
The event status. Valid values:
|
toBeConfirmed |
| Note |
string |
The remarks. |
already confirmed. |
| EventScope |
string |
The dimension of the security event. Valid values:
|
ip |
| DetailValue |
string |
The detailed information about the security event. The value is a string converted from a JSON object constructed by a series of parameters. |
{\"location\":[\"FR\",\"CN\"],\"location_type\":\"country\"} |
Examples
Success response
JSON format
{
"RequestId": "D7861F61-5B61-46CE-A47C-6B19160D5EB0",
"EventId": "18ba94fea9***e66ba0557b7b91",
"EventTag": "ObtainSensitiveUnauthorized",
"AttackerList": [
"104.234.140.**"
],
"AttackCnt": "345",
"StartTs": "1683648000",
"EndTs": "1683703260",
"Origin": "custom",
"EventLevel": "low",
"UserStatus": "toBeConfirmed",
"Note": "already confirmed.",
"EventScope": "ip",
"DetailValue": "{\\\"location\\\":[\\\"FR\\\",\\\"CN\\\"],\\\"location_type\\\":\\\"country\\\"}"
}
Error codes
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.