GetIncidentInvestigation - 获取事件AI调查详情

更新时间:
复制 MD 格式

查询指定事件的 AI 调查详情,包括报告标识、调查时间、研判分类、摘要、结论和报告内容。

接口说明

查询指定事件已生成的 AI 调查结果。可先调用 ListIncidentInvestigations 获取报告 ID 或显示 ID,再调用本接口查询详情。

查询优先级如下:

  1. 指定 IncidentInvestigationId 时,按报告 ID 查询。

  2. 未指定报告 ID,但指定 IncidentInvestigationDisplayId 时,按显示 ID 查询。

  3. 两个标识都未指定时,返回 IncidentUuid 对应事件最近一次成功完成的调查结果,按调查结束时间倒序选取。

未找到匹配的调查记录时,IncidentInvestigation 为空。

IncidentInvestigationStatus 表示报告中的研判分类。IncidentInvestigationReport 和 IncidentInvestigationOutput 均为 JSON 格式的字符串,使用其中的字段前需要先进行 JSON 解析;内部字段可能随报告版本变化,调用方应兼容缺失字段。示例仅展示部分报告内容。

调试

您可以在OpenAPI Explorer中直接运行该接口,免去您计算签名的困扰。运行成功后,OpenAPI Explorer可以自动生成SDK代码示例。

调试

授权信息

当前API暂无授权信息透出。

请求参数

名称

类型

必填

描述

示例值

RegionId

string

否

威胁分析的数据管理中心所在地。您需要根据资产所在地域,选择管理中心所在地。取值:

  • cn-hangzhou:资产属于中国内地。

  • ap-southeast-1:资产属于海外地域。

cn-hangzhou

Lang

string

否

返回消息的语言类型。取值:

  • zh(默认):中文。

  • en:英文。

zh

RoleFor

integer

否

管理员切换成其他成员视角的用户 ID。

113091674488****

IncidentUuid

string

是

事件的全局唯一标识。未指定报告 ID 和显示 ID 时,按该事件查询最近一次成功完成的调查结果。

85ea4241-798f-4684-a876-65d4f0c3****

IncidentInvestigationId

string

否

AI 调查报告 ID,可从 ListIncidentInvestigations 返回的 IncidentInvestigationId 获取。与 IncidentInvestigationDisplayId 同时传入时,优先使用本参数。

951a6a0b-14c7-4332-ace6-bff21c******

IncidentInvestigationDisplayId

string

否

AI 调查报告的显示 ID,可从 ListIncidentInvestigations 返回的 IncidentInvestigationDisplayId 获取。仅在未传入 IncidentInvestigationId 时生效;两个标识都不传时,查询指定事件最近一次成功完成的调查结果。

755616bb5d63046c1e4f62ea872a****

返回参数

名称

类型

描述

示例值

object

请求返回的数据。

IncidentInvestigation

object

事件的 AI 调查详情。未找到匹配的调查记录时为空。

IncidentInvestigationAlertName

string

触发本次 AI 调查的告警名称。

Webshell告警

IncidentInvestigationConclusion

string

AI 调查的研判结论,对应报告中的 ai_judgement_conclusion。

现有证据不足,无法确认攻击链是否完整,建议补充关联日志后进一步分析。

IncidentInvestigationDisplayId

string

AI 调查报告的显示 ID,可作为本接口的 IncidentInvestigationDisplayId 入参查询该报告。

755616bb5d63046c1e4f62ea872a****

IncidentInvestigationEndTime

integer

AI 调查结束时间,Unix 时间戳,单位为秒。未记录执行结束时间时,使用调查记录的最后更新时间;两者都不存在时为空。

1786195753

IncidentInvestigationId

string

AI 调查报告的唯一 ID,可作为本接口的 IncidentInvestigationId 入参查询该报告。

951a6a0b-14c7-4332-ace6-bff21c******

IncidentInvestigationOutput

string

AI 调查的输出内容,采用 JSON 格式的字符串。可包含 investigation_report(调查过程与证据正文,其内容可使用 Markdown 格式)等字段;未生成对应输出时为空,内部字段随报告版本变化。

{"investigation_report":"### 调查结果\n检测到可疑文件,尚缺少执行证据。"}

IncidentInvestigationReport

string

AI 调查报告内容,采用 JSON 格式的字符串。可包含 judgement_category(研判分类)、ai_judgement_conclusion(研判结论)、ai_summary(摘要)以及攻击过程、攻击图谱等字段;具体内容随报告版本变化。

{"judgement_category":"insufficient_information_to_evaluate","ai_judgement_conclusion":"现有证据不足,无法确认攻击链是否完整,建议补充关联日志后进一步分析。","ai_summary":"检测到可疑文件,现有证据不足以确认攻击是否成功。"}

IncidentInvestigationStartTime

integer

AI 调查开始时间,Unix 时间戳,单位为秒。未记录执行开始时间时,使用调查记录的创建时间;两者都不存在时为空。

1786195533

IncidentInvestigationStatus

string

AI 调查报告的研判分类,对应报告中的 judgement_category,不表示异步任务的执行状态。取值:

  • real_attack:真实攻击。

  • blocked:风险阻断。

  • false_positive:疑似误报。

  • insufficient_information_to_evaluate:无法研判。

insufficient_information_to_evaluate

IncidentInvestigationSummary

string

AI 调查报告的摘要,对应调查结果中的 ai_summary。

检测到可疑文件,现有证据不足以确认攻击是否成功。

IncidentUuid

string

事件全局唯一 UUID。

9f00c254391400f6898c4d4fea******

RequestId

string

请求 ID,用于定位和排查本次调用。

9AAA9ED9-78F4-5021-86DC-D51C7511****

示例

正常返回示例

JSON格式

{
  "IncidentInvestigation": {
    "IncidentInvestigationAlertName": "Webshell告警",
    "IncidentInvestigationConclusion": "现有证据不足,无法确认攻击链是否完整,建议补充关联日志后进一步分析。",
    "IncidentInvestigationDisplayId": "755616bb5d63046c1e4f62ea872a****",
    "IncidentInvestigationEndTime": 1786195753,
    "IncidentInvestigationId": "951a6a0b-14c7-4332-ace6-bff21c******",
    "IncidentInvestigationOutput": "{\"investigation_report\":\"### 调查结果\\n检测到可疑文件,尚缺少执行证据。\"}",
    "IncidentInvestigationReport": "{\"judgement_category\":\"insufficient_information_to_evaluate\",\"ai_judgement_conclusion\":\"现有证据不足,无法确认攻击链是否完整,建议补充关联日志后进一步分析。\",\"ai_summary\":\"检测到可疑文件,现有证据不足以确认攻击是否成功。\"}",
    "IncidentInvestigationStartTime": 1786195533,
    "IncidentInvestigationStatus": "insufficient_information_to_evaluate",
    "IncidentInvestigationSummary": "检测到可疑文件,现有证据不足以确认攻击是否成功。",
    "IncidentUuid": "9f00c254391400f6898c4d4fea******"
  },
  "RequestId": "9AAA9ED9-78F4-5021-86DC-D51C7511****"
}

错误码

HTTP status code

错误码

错误信息

描述

400 IdempotentParameterMismatch The request uses the same client token as a previous, but non-identical request. Do not reuse a client token with different requests, unless the requests are identical.

访问错误中心查看更多错误码。

变更历史

更多信息,参考变更详情。