查询指定事件的 AI 调查详情,包括报告标识、调查时间、研判分类、摘要、结论和报告内容。
接口说明
查询指定事件已生成的 AI 调查结果。可先调用 ListIncidentInvestigations 获取报告 ID 或显示 ID,再调用本接口查询详情。
查询优先级如下:
指定 IncidentInvestigationId 时,按报告 ID 查询。
未指定报告 ID,但指定 IncidentInvestigationDisplayId 时,按显示 ID 查询。
两个标识都未指定时,返回 IncidentUuid 对应事件最近一次成功完成的调查结果,按调查结束时间倒序选取。
未找到匹配的调查记录时,IncidentInvestigation 为空。
IncidentInvestigationStatus 表示报告中的研判分类。IncidentInvestigationReport 和 IncidentInvestigationOutput 均为 JSON 格式的字符串,使用其中的字段前需要先进行 JSON 解析;内部字段可能随报告版本变化,调用方应兼容缺失字段。示例仅展示部分报告内容。
调试
您可以在OpenAPI Explorer中直接运行该接口,免去您计算签名的困扰。运行成功后,OpenAPI Explorer可以自动生成SDK代码示例。
调试
授权信息
请求参数
|
名称 |
类型 |
必填 |
描述 |
示例值 |
| RegionId |
string |
否 |
威胁分析的数据管理中心所在地。您需要根据资产所在地域,选择管理中心所在地。取值:
|
cn-hangzhou |
| Lang |
string |
否 |
返回消息的语言类型。取值:
|
zh |
| RoleFor |
integer |
否 |
管理员切换成其他成员视角的用户 ID。 |
113091674488**** |
| IncidentUuid |
string |
是 |
事件的全局唯一标识。未指定报告 ID 和显示 ID 时,按该事件查询最近一次成功完成的调查结果。 |
85ea4241-798f-4684-a876-65d4f0c3**** |
| IncidentInvestigationId |
string |
否 |
AI 调查报告 ID,可从 ListIncidentInvestigations 返回的 IncidentInvestigationId 获取。与 IncidentInvestigationDisplayId 同时传入时,优先使用本参数。 |
951a6a0b-14c7-4332-ace6-bff21c****** |
| IncidentInvestigationDisplayId |
string |
否 |
AI 调查报告的显示 ID,可从 ListIncidentInvestigations 返回的 IncidentInvestigationDisplayId 获取。仅在未传入 IncidentInvestigationId 时生效;两个标识都不传时,查询指定事件最近一次成功完成的调查结果。 |
755616bb5d63046c1e4f62ea872a**** |
返回参数
|
名称 |
类型 |
描述 |
示例值 |
|
object |
请求返回的数据。 |
||
| IncidentInvestigation |
object |
事件的 AI 调查详情。未找到匹配的调查记录时为空。 |
|
| IncidentInvestigationAlertName |
string |
触发本次 AI 调查的告警名称。 |
Webshell告警 |
| IncidentInvestigationConclusion |
string |
AI 调查的研判结论,对应报告中的 ai_judgement_conclusion。 |
现有证据不足,无法确认攻击链是否完整,建议补充关联日志后进一步分析。 |
| IncidentInvestigationDisplayId |
string |
AI 调查报告的显示 ID,可作为本接口的 IncidentInvestigationDisplayId 入参查询该报告。 |
755616bb5d63046c1e4f62ea872a**** |
| IncidentInvestigationEndTime |
integer |
AI 调查结束时间,Unix 时间戳,单位为秒。未记录执行结束时间时,使用调查记录的最后更新时间;两者都不存在时为空。 |
1786195753 |
| IncidentInvestigationId |
string |
AI 调查报告的唯一 ID,可作为本接口的 IncidentInvestigationId 入参查询该报告。 |
951a6a0b-14c7-4332-ace6-bff21c****** |
| IncidentInvestigationOutput |
string |
AI 调查的输出内容,采用 JSON 格式的字符串。可包含 investigation_report(调查过程与证据正文,其内容可使用 Markdown 格式)等字段;未生成对应输出时为空,内部字段随报告版本变化。 |
{"investigation_report":"### 调查结果\n检测到可疑文件,尚缺少执行证据。"} |
| IncidentInvestigationReport |
string |
AI 调查报告内容,采用 JSON 格式的字符串。可包含 judgement_category(研判分类)、ai_judgement_conclusion(研判结论)、ai_summary(摘要)以及攻击过程、攻击图谱等字段;具体内容随报告版本变化。 |
{"judgement_category":"insufficient_information_to_evaluate","ai_judgement_conclusion":"现有证据不足,无法确认攻击链是否完整,建议补充关联日志后进一步分析。","ai_summary":"检测到可疑文件,现有证据不足以确认攻击是否成功。"} |
| IncidentInvestigationStartTime |
integer |
AI 调查开始时间,Unix 时间戳,单位为秒。未记录执行开始时间时,使用调查记录的创建时间;两者都不存在时为空。 |
1786195533 |
| IncidentInvestigationStatus |
string |
AI 调查报告的研判分类,对应报告中的 judgement_category,不表示异步任务的执行状态。取值:
|
insufficient_information_to_evaluate |
| IncidentInvestigationSummary |
string |
AI 调查报告的摘要,对应调查结果中的 ai_summary。 |
检测到可疑文件,现有证据不足以确认攻击是否成功。 |
| IncidentUuid |
string |
事件全局唯一 UUID。 |
9f00c254391400f6898c4d4fea****** |
| RequestId |
string |
请求 ID,用于定位和排查本次调用。 |
9AAA9ED9-78F4-5021-86DC-D51C7511**** |
示例
正常返回示例
JSON格式
{
"IncidentInvestigation": {
"IncidentInvestigationAlertName": "Webshell告警",
"IncidentInvestigationConclusion": "现有证据不足,无法确认攻击链是否完整,建议补充关联日志后进一步分析。",
"IncidentInvestigationDisplayId": "755616bb5d63046c1e4f62ea872a****",
"IncidentInvestigationEndTime": 1786195753,
"IncidentInvestigationId": "951a6a0b-14c7-4332-ace6-bff21c******",
"IncidentInvestigationOutput": "{\"investigation_report\":\"### 调查结果\\n检测到可疑文件,尚缺少执行证据。\"}",
"IncidentInvestigationReport": "{\"judgement_category\":\"insufficient_information_to_evaluate\",\"ai_judgement_conclusion\":\"现有证据不足,无法确认攻击链是否完整,建议补充关联日志后进一步分析。\",\"ai_summary\":\"检测到可疑文件,现有证据不足以确认攻击是否成功。\"}",
"IncidentInvestigationStartTime": 1786195533,
"IncidentInvestigationStatus": "insufficient_information_to_evaluate",
"IncidentInvestigationSummary": "检测到可疑文件,现有证据不足以确认攻击是否成功。",
"IncidentUuid": "9f00c254391400f6898c4d4fea******"
},
"RequestId": "9AAA9ED9-78F4-5021-86DC-D51C7511****"
}
错误码
|
HTTP status code |
错误码 |
错误信息 |
描述 |
|---|---|---|---|
| 400 | IdempotentParameterMismatch | The request uses the same client token as a previous, but non-identical request. Do not reuse a client token with different requests, unless the requests are identical. |
访问错误中心查看更多错误码。
变更历史
更多信息,参考变更详情。