GetOpSensitiveData

Updated at:

Queries the records that are generated on a specified date for access to sensitive data in all the DataWorks workspaces of a tenant.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

No authorization for this operation. If you encounter issues with this operation, contact technical support.

Request parameters

Parameter

Type

Required

Description

Example

Name

string

Yes

The parameters that you can configure to query the access records. Valid values:

  • dbType: Data type.

  • instanceName: Instance name.

  • databaseName: Database name.

  • projectName: Project name.

  • clusterName: Cluster name.

The following example shows the parameters configured to query the access records of the sensitive data in the abc database of the Hologres instance ABC: [ {"dbType":"hologres","instanceName":"ABC","databaseName":"abc"} ]

You must configure the parameters based on the compute engine that you use in your business.

[ {"dbType":"hologres","instanceName":"ABC","databaseName":"abc"}, {"dbType":"ODPS.ODPS","projectName":"adbc"} ]

PageSize

integer

Yes

The number of entries per page. Minimum value: 1. Maximum value: 1000.

1

PageNo

integer

Yes

The page number. Valid values: 1 to 1000.

10

Date

string

Yes

The date on which access records were generated. Specify the value in the yyyyMMdd format.

20210116

OpType

string

No

The operation that is performed on the data. Valid values:

  • SQL_SELECT: specifies the data access operation. For example, execute a SELECT statement to query data.

  • TUNNEL_DOWNLOAD: specifies the data download operation. For example, run a Tunnel command to download data.

SQL_SELECT

Response elements

Element

Type

Description

Example

object

The returned result.

OpSensitiveData

string

The information about the access records of the sensitive data. The information includes totalCount and opRiskDatas. opRiskDatas includes the following parameters:

  • sensType: the type of the sensitive data.

  • sensLevel: the sensitivity level of the sensitive data. A larger value indicates a higher sensitivity level.

  • opType: the type of the operation.

  • sql: the SQL statement that is executed.

  • opAccount: the account that is used to perform the operation.

  • opTime: the time when the operation was performed.

"opSensDatas": [ { "sensLevel": "L4", "opTime": "2021-02-07 00:14:51", "opAccount": "ALIYUN$dsg_test", "sensType": "Mobile phone number", "sql": "select * from dsg_demo.tbl_phonebook where phone_no = '1331111****';" } ], "totalCount": 6

RequestId

string

The request ID.

0000-ABCD-EFG****

Examples

Success response

JSON format

{
  "OpSensitiveData": "\"opSensDatas\": [       {         \"sensLevel\": \"L4\",         \"opTime\": \"2021-02-07 00:14:51\",         \"opAccount\": \"ALIYUN$dsg_test\",         \"sensType\": \"Mobile phone number\",         \"sql\": \"select * from dsg_demo.tbl_phonebook where phone_no = '1331111****';\"       }     ],     \"totalCount\": 6",
  "RequestId": "0000-ABCD-EFG****"
}

Error codes

HTTP status code

Error code

Error message

Description

400 Invalid.Param The request parameter is invalid.
500 InternalError.DQC.BizError An internal error occurred.
403 Forbidden.NoTenant The tenant information cannot be obtained using user ID.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.