GetNormalizationRule
Retrieves normalization rule information.
Operation description
The request parameter JsonConfig contains highly complex JSON configurations. To help you configure it, we provide a utility class with specific configuration examples. For more information, refer to Demo.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:GetNormalizationRule |
get |
*NormalizationRule
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| RegionId |
string |
No |
The region where the data management center of Threat Analysis is located. You must select the region of the management center based on the region where your assets are located. Valid values:
|
cn-hangzhou |
| Lang |
string |
No |
The language of the response message. Valid values:
|
zh |
| RoleFor |
integer |
No |
The ID of the user whose perspective the administrator switches to. |
173326******* |
| NormalizationRuleId |
string |
No |
The ID of the normalization rule. |
nr-z0b2ssjteut85uoh9nzp |
| NormalizationSecurityDomainId |
string |
No |
The ID of the normalization security domain. |
NETWORK_AND_WEB_SECURITY |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response body. |
||
| RequestId |
string |
The ID of the request. |
6276D891-*****-55B2-87B9-74D413F7**** |
| NormalizationRule |
object |
The normalization rule. |
|
| CreateTime |
integer |
The creation time. The value is a UNIX timestamp in milliseconds. |
1733269771123 |
| UpdateTime |
integer |
The update time. The value is a UNIX timestamp in milliseconds. |
1733269771123 |
| NormalizationRuleId |
string |
The ID of the normalization rule. |
nr-z0b2ssjteut85uoh9nzp |
| NormalizationRuleName |
string |
The name of the normalization rule. |
normalization_rule_Z57np |
| NormalizationRuleType |
string |
The type of the normalization rule. Valid values:
|
predefined |
| NormalizationRuleFormat |
string |
The format of the normalization rule. |
SPL |
| NormalizationRuleDescription |
string |
The description of the normalization rule. |
normalization_rule_Z57np |
| NormalizationRuleVersion |
integer |
The version of the normalization rule. |
V1 |
| NormalizationRuleExpression |
string |
The expression of the normalization rule. |
* | pack-fields -include='[\s\S]+' as extend_content |
| NormalizationRuleStatus |
string |
The status of the normalization rule. |
started |
| NormalizationCategoryId |
string |
The category ID of the normalization rule. |
NETWORK_CATEGORY |
| NormalizationSchemaId |
string |
The ID of the normalization schema. |
HTTP_ACTIVITY |
| NormalizationSecurityDomainId |
string |
The ID of the normalization security domain. |
NETWORK_AND_WEB_SECURITY |
| VendorId |
string |
The ID of the vendor corresponding to the normalization rule. |
alibaba_cloud |
| ProductId |
string |
The product ID. |
alibaba_cloud_sas |
| NormalizationRuleMode |
string |
The mode of the normalization rule. Valid values:
|
both |
| NormalizationFieldSource |
string |
The field source:
|
normalized |
| ExtendContentPacked |
string |
Specifies whether to pack non-standard fields into the extended field extend_content. Valid values:
|
enabled |
| OrderField |
string |
The field used to sort the rule list. Valid values:
|
GmtModified |
| NormalizationRuleIds |
array |
The IDs of the normalization rules. |
|
|
string |
The IDs of the normalization rules. |
nr-z0b2ssjteut85uoh9nzp |
|
| ExtendFieldStoreMode |
string |
The storage mode for extended fields. Valid values: flat (ingest as-is), reject (do not ingest), and pack (pack into the extend_content field). |
flat |
Examples
Success response
JSON format
{
"RequestId": "6276D891-*****-55B2-87B9-74D413F7****",
"NormalizationRule": {
"CreateTime": 1733269771123,
"UpdateTime": 1733269771123,
"NormalizationRuleId": "nr-z0b2ssjteut85uoh9nzp",
"NormalizationRuleName": "normalization_rule_Z57np",
"NormalizationRuleType": "predefined",
"NormalizationRuleFormat": "SPL",
"NormalizationRuleDescription": "normalization_rule_Z57np",
"NormalizationRuleVersion": 0,
"NormalizationRuleExpression": "* | pack-fields -include='[\\s\\S]+' as extend_content",
"NormalizationRuleStatus": "started",
"NormalizationCategoryId": "NETWORK_CATEGORY",
"NormalizationSchemaId": "HTTP_ACTIVITY",
"NormalizationSecurityDomainId": "NETWORK_AND_WEB_SECURITY",
"VendorId": "alibaba_cloud",
"ProductId": "alibaba_cloud_sas",
"NormalizationRuleMode": "both",
"NormalizationFieldSource": "normalized",
"ExtendContentPacked": "enabled",
"OrderField": "GmtModified",
"NormalizationRuleIds": [
"nr-z0b2ssjteut85uoh9nzp"
],
"ExtendFieldStoreMode": "flat"
}
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | IdempotentParameterMismatch | The request uses the same client token as a previous, but non-identical request. Do not reuse a client token with different requests, unless the requests are identical. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.