GetOpRiskData

Updated at:

Queries risky sensitive data access records generated on a specified date in all DataWorks workspaces of a tenant.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

No authorization for this operation. If you encounter issues with this operation, contact technical support.

Request parameters

Parameter

Type

Required

Description

Example

PageSize

integer

Yes

The number of entries per page. Maximum value: 1000.

10

PageNo

integer

Yes

The page number. Pages start from 1.

1

Name

string

No

The parameters that you can configure to query the access records. Valid values:

  • dbType: Data type.

  • instanceName: Instance name.

  • databaseName: Database name.

  • projectName: Project name.

  • clusterName: Cluster name.

The following example shows the parameters configured to query the access records of the sensitive data in the abc database of the Hologres instance ABC: [ {"dbType":"hologres","instanceName":"ABC","databaseName":"abc"} ]

You must configure the parameters based on the compute engine that you use in your business.

[ {"dbType":"hologres","instanceName":"ABC","databaseName":"abc"}, {"dbType":"ODPS.ODPS","projectName":"adbc"} ]

Date

string

Yes

The date on which access records were generated. Specify the value in the yyyyMMdd format.

20210221

RiskType

string

No

The method that you use to identify risks.

  • You can manually identify risks.

  • You can also use a risk identification rule to identify risks. You can log on to the DataWorks console and go to the Risk Identification Rules page in Data Security Guard to obtain the name of the rule.

Manual identification

Response elements

Element

Type

Description

Example

object

The returned results.

RiskData

string

The information about the high-risk sensitive data. The information includes totalCount and opRiskDatas. opRiskDatas includes the following parameters:

  • sensType: the type of the sensitive data

  • sensLevel: the sensitivity level of the sensitive data

  • opType: the type of the operation

  • sql: the SQL statement that is executed

  • opAccount: the account that is used to perform the operation

  • opTime: the time when the operation was performed

{ "opRiskDatas": [ { "riskType": "Hierarchical dimension, EMR engine dimension and project dimension, EMR engine project dimension operation data, export method dimension, EMR engine", "opTime": "2021-01-04 23:39:13", "opType": "SQL_SELECT", "opAccount": "user", "sensType": "Email/name/mobile phone number", "sql": "SELECT * FROM default.jiade_1219_test_create LIMIT 20" } ], "totalCount": 499 }

RequestId

string

The request ID.

0000-ABCD-EFG****

Examples

Success response

JSON format

{
  "RiskData": "{     \"opRiskDatas\": [       {         \"riskType\": \"Hierarchical dimension, EMR engine dimension and project dimension, EMR engine project dimension operation data, export method dimension, EMR engine\",         \"opTime\": \"2021-01-04 23:39:13\",         \"opType\": \"SQL_SELECT\",         \"opAccount\": \"user\",         \"sensType\": \"Email/name/mobile phone number\",         \"sql\": \"SELECT * FROM default.jiade_1219_test_create LIMIT 20\"       }     ],     \"totalCount\": 499   }",
  "RequestId": "0000-ABCD-EFG****"
}

Error codes

HTTP status code

Error code

Error message

Description

400 Invalid.Param The request parameter is invalid.
500 InternalError.DQC.BizError An internal error occurred.
403 Forbidden.NoTenant The tenant information cannot be obtained using user ID.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.