ListEntities
Queries a list of entities.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:ListEntities |
get |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| IncidentUuid |
string |
Yes |
The event ID. |
85ea4241-798f-4684-a876-65d4f0c3**** |
| EntityType |
string |
No |
The entity type. Valid values:
|
ip |
| EntityName |
string |
No |
The entity name. |
host1**** |
| EntityUuid |
string |
No |
The entity UUID. |
6c740667-80b2-476d-8924-2e706feb**** |
| EntityUuids |
string |
No |
A comma-separated list of entity UUIDs. |
6c740667-80b2-476d-8924-2e706feb****,6c740667-80b2-476d-8924-2e706feb**** |
| MalwareType |
string |
No |
The malicious entity type. |
aliyun.siem.sas.alert_tag.miner_software |
| IsMalwareEntity |
string |
No |
Specifies whether the entity is malicious. Valid values:
|
1 |
| Tags |
string |
No |
The tags of the entity, provided as a string in JSON array format.
|
[{"tagKey1":"tagValue1"},{"tagKey2":"tagValue2"}] |
| CurrentPage |
integer |
Yes |
The page number of the results to return. The minimum value is 1. |
1 |
| PageSize |
integer |
Yes |
The number of entries per page. Maximum value: 100. |
10 |
| RoleType |
integer |
No |
The view type. Valid values:
|
1 |
| RoleFor |
integer |
No |
The user ID of a member account. An administrator can use this parameter to query data from the perspective of that specific account. |
113091674488**** |
| RegionId |
string |
No |
The region of the data management center for Threat Analysis. Select the region where your assets are deployed. Valid values:
|
cn-hangzhou |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
PageResponse<List |
||
| Success |
boolean |
Indicates whether the request was successful. Valid values:
|
true |
| Code |
integer |
The HTTP status code. |
200 |
| Message |
string |
The response message. |
success |
| RequestId |
string |
The request ID. |
9AAA9ED9-78F4-5021-86DC-D51C7511**** |
| Data |
object |
The response data. |
123456 |
| PageInfo |
object |
The pagination details. |
|
| CurrentPage |
integer |
The current page number. |
1 |
| PageSize |
integer |
The number of entries per page. |
10 |
| TotalCount |
integer |
The total number of entries. |
100 |
| ResponseData |
array<object> |
The list of entities. |
|
|
array<object> |
|||
| Id |
integer |
The entity ID. |
123456789*** |
| GmtCreate |
string |
The time when the entity was created. |
2021-01-06 16:37:29 |
| GmtModified |
string |
The time when the entity was last updated. |
2021-01-06 16:37:29 |
| Aliuid |
integer |
The ID of the Alibaba Cloud account. |
123456789**** |
| IncidentUuid |
string |
The UUID of the incident. You can obtain this value from the response of the |
85ea4241-798f-4684-a876-65d4f0c3**** |
| AlertUuid |
string |
The UUID of the alert. |
sas_71e24437d2797ce8fc59692905a4**** |
| AlertNum |
integer |
The number of alerts associated with the entity. |
1 |
| EventNum |
integer |
The number of events associated with the entity. |
1 |
| CloudCode |
string |
The cloud service provider. Valid values:
|
aliyun |
| EntityType |
string |
The entity type. Valid values:
|
ip |
| EntityName |
string |
The entity name. |
123.123.123.123 |
| EntityInfo |
string |
Details about the entity, in JSON format. |
{"file_path": "c:/www/leixi.jsp","file_hash": "aa0ca926ad948cd820e0a3d9a18c****","host_uuid": "efed2cf7-0b77-45d9-a97b-d2cf246b****","malware_type": "${aliyun.siem.sas.alert_tag.webshell}","host_name": "launch-advisor-2023****"} |
| SubUserId |
integer |
The ID of the sub-account associated with the entity. |
113091674488**** |
| EntityId |
string |
The logical ID of the entity. |
12345**** |
| EntityUuid |
string |
The UUID of the entity. |
8087b3e4aa6862852c100c8738cf**** |
| MalwareType |
string |
The malware type. |
aliyun.siem.sas.alert_tag.webshell |
| IsAsset |
string |
Specifies whether the entity is an asset. Valid values:
|
1 |
| IsMalware |
string |
Specifies whether the entity is malicious. Valid values:
|
0 |
| Tags |
string |
The tags of the entity, represented as a string-formatted JSON array.
|
[{"tagKey1":"tagValue1"},{"tagKey2":"tagValue2"}] |
| AgentDisposalMethod |
string |
The agent's recommended response method. |
delete_file |
| AgentDisposalPlaybookUuid |
string |
The UUID of the agent's recommended response playbook. |
12XAD-SFQ-WAF-2ca2 |
| AgentDisposalSuggestion |
string |
The agent's recommended response suggestion. |
{} |
| AgentConfidence |
string |
The agent's confidence score for the entity. |
85 |
| AgentDisposes |
array<object> |
A list of recommended response actions from the agent. |
|
|
object |
A recommended response action. |
||
| AgentDisposalPlaybookUuid |
string |
The UUID of the agent's recommended response playbook. |
12XAD-SFQ-WAF-2ca2 |
| AgentDisposalMethod |
string |
The agent's recommended response method. |
{} |
Examples
Success response
JSON format
{
"Success": true,
"Code": 200,
"Message": "success",
"RequestId": "9AAA9ED9-78F4-5021-86DC-D51C7511****",
"Data": {
"PageInfo": {
"CurrentPage": 1,
"PageSize": 10,
"TotalCount": 100
},
"ResponseData": [
{
"Id": 0,
"GmtCreate": "2021-01-06 16:37:29",
"GmtModified": "2021-01-06 16:37:29",
"Aliuid": 0,
"IncidentUuid": "85ea4241-798f-4684-a876-65d4f0c3****",
"AlertUuid": "sas_71e24437d2797ce8fc59692905a4****",
"AlertNum": 1,
"EventNum": 1,
"CloudCode": "aliyun",
"EntityType": "ip",
"EntityName": "123.123.123.123",
"EntityInfo": "{\"file_path\": \"c:/www/leixi.jsp\",\"file_hash\": \"aa0ca926ad948cd820e0a3d9a18c****\",\"host_uuid\": \"efed2cf7-0b77-45d9-a97b-d2cf246b****\",\"malware_type\": \"${aliyun.siem.sas.alert_tag.webshell}\",\"host_name\": \"launch-advisor-2023****\"}",
"SubUserId": 0,
"EntityId": "12345****",
"EntityUuid": "8087b3e4aa6862852c100c8738cf****",
"MalwareType": "aliyun.siem.sas.alert_tag.webshell",
"IsAsset": "1",
"IsMalware": "0",
"Tags": "[{\"tagKey1\":\"tagValue1\"},{\"tagKey2\":\"tagValue2\"}]",
"AgentDisposalMethod": "delete_file",
"AgentDisposalPlaybookUuid": "12XAD-SFQ-WAF-2ca2",
"AgentDisposalSuggestion": "{}",
"AgentConfidence": "85",
"AgentDisposes": [
{
"AgentDisposalPlaybookUuid": "12XAD-SFQ-WAF-2ca2",
"AgentDisposalMethod": "{}"
}
]
}
]
}
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 500 | InternalError | The request processing has failed due to some unknown error. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.