导出防火墙日志
功能介绍
导出防火墙日志
调用方法
请参见如何调用API。
URI
POST /v1/{project_id}/cfw/{fw_instance_id}/logs/export
请求参数
参数 |
是否必选 |
参数类型 |
描述 |
---|---|---|---|
filters |
否 |
Array of Filter objects |
参数解释: 过滤条件 约束限制: 不涉及 取值范围: 1-1024 默认取值: 不涉及 |
start_time |
是 |
Long |
参数解释: 开始时间 约束限制: 不涉及 取值范围: 毫秒级时间戳 默认取值: 不涉及 |
end_time |
是 |
Long |
参数解释: 结束时间 约束限制: 不涉及 取值范围: 毫秒级时间戳 默认取值: 不涉及 |
log_type |
是 |
String |
参数解释: 日志类型 约束限制: 不涉及 取值范围: internet为南北向日志、nat为nat场景日志,vpc为东西向日志,vgw为vgw场景日志 默认取值: 不涉及 |
type |
是 |
String |
参数解释: 日志类型 约束限制: 不涉及 取值范围: attack为攻击日志、acl 访问控制日志,flow 流量日志,url url日志 默认取值: 不涉及 |
time_zone |
否 |
String |
参数解释: 时区 约束限制: 不涉及 取值范围: "GMT+08:00" 默认取值: 不涉及 |
响应参数
状态码:200
参数 |
参数类型 |
描述 |
---|---|---|
- |
File |
状态码:400
参数 |
参数类型 |
描述 |
---|---|---|
error_code |
String |
参数解释: 错误码 取值范围: 不涉及 |
error_msg |
String |
参数解释: 错误描述 取值范围: 不涉及 |
请求示例
项目ID为a16df7cf1d094befa6bbc72cbf51e93a,防火墙ID为fcd04edd-428a-4631-bef5-46a924293cca,时间范围为1751958412875到1751969212875,过滤条件为目的IP为方向为100.85.219.117,目的端口为55637,导出互联网边界的流量日志
https://{Endpoint}/v1/a16df7cf1d094befa6bbc72cbf51e93a/cfw/fcd04edd-428a-4631-bef5-46a924293cca/logs/export { "filters" : [ { "field" : "dst_ip", "operator" : "equal", "values" : [ "100.85.219.117" ] }, { "field" : "src_port", "operator" : "equal", "values" : [ "55637" ] } ], "start_time" : 1751958412875, "end_time" : 1751969212875, "type" : "flow", "log_type" : "internet", "time_zone" : "GMT%2B08:00" }
响应示例
状态码:400
Bad Request
{ "error_code" : "CFW.00200003", "error_msg" : "参数错误" }
SDK代码示例
SDK代码示例如下。
项目ID为a16df7cf1d094befa6bbc72cbf51e93a,防火墙ID为fcd04edd-428a-4631-bef5-46a924293cca,时间范围为1751958412875到1751969212875,过滤条件为目的IP为方向为100.85.219.117,目的端口为55637,导出互联网边界的流量日志
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 |
package com.huaweicloud.sdk.test; import com.huaweicloud.sdk.core.auth.ICredential; import com.huaweicloud.sdk.core.auth.BasicCredentials; import com.huaweicloud.sdk.core.exception.ConnectionException; import com.huaweicloud.sdk.core.exception.RequestTimeoutException; import com.huaweicloud.sdk.core.exception.ServiceResponseException; import com.huaweicloud.sdk.cfw.v1.region.CfwRegion; import com.huaweicloud.sdk.cfw.v1.*; import com.huaweicloud.sdk.cfw.v1.model.*; import java.util.List; import java.util.ArrayList; public class ExportLogsSolution { public static void main(String[] args) { // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment String ak = System.getenv("CLOUD_SDK_AK"); String sk = System.getenv("CLOUD_SDK_SK"); String projectId = "{project_id}"; ICredential auth = new BasicCredentials() .withProjectId(projectId) .withAk(ak) .withSk(sk); CfwClient client = CfwClient.newBuilder() .withCredential(auth) .withRegion(CfwRegion.valueOf("<YOUR REGION>")) .build(); ExportLogsRequest request = new ExportLogsRequest(); request.withFwInstanceId("{fw_instance_id}"); ExportLogsRequestBody body = new ExportLogsRequestBody(); List<String> listFiltersValues = new ArrayList<>(); listFiltersValues.add("55637"); List<String> listFiltersValues1 = new ArrayList<>(); listFiltersValues1.add("100.85.219.117"); List<Filter> listbodyFilters = new ArrayList<>(); listbodyFilters.add( new Filter() .withField("dst_ip") .withValues(listFiltersValues1) .withOperator(Filter.OperatorEnum.fromValue("equal")) ); listbodyFilters.add( new Filter() .withField("src_port") .withValues(listFiltersValues) .withOperator(Filter.OperatorEnum.fromValue("equal")) ); body.withTimeZone("GMT%2B08:00"); body.withType(ExportLogsRequestBody.TypeEnum.fromValue("flow")); body.withLogType(ExportLogsRequestBody.LogTypeEnum.fromValue("internet")); body.withEndTime(1751969212875L); body.withStartTime(1751958412875L); body.withFilters(listbodyFilters); request.withBody(body); try { ExportLogsResponse response = client.exportLogs(request); System.out.println(response.toString()); } catch (ConnectionException e) { e.printStackTrace(); } catch (RequestTimeoutException e) { e.printStackTrace(); } catch (ServiceResponseException e) { e.printStackTrace(); System.out.println(e.getHttpStatusCode()); System.out.println(e.getRequestId()); System.out.println(e.getErrorCode()); System.out.println(e.getErrorMsg()); } } } |
项目ID为a16df7cf1d094befa6bbc72cbf51e93a,防火墙ID为fcd04edd-428a-4631-bef5-46a924293cca,时间范围为1751958412875到1751969212875,过滤条件为目的IP为方向为100.85.219.117,目的端口为55637,导出互联网边界的流量日志
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 |
# coding: utf-8 import os from huaweicloudsdkcore.auth.credentials import BasicCredentials from huaweicloudsdkcfw.v1.region.cfw_region import CfwRegion from huaweicloudsdkcore.exceptions import exceptions from huaweicloudsdkcfw.v1 import * if __name__ == "__main__": # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment ak = os.environ["CLOUD_SDK_AK"] sk = os.environ["CLOUD_SDK_SK"] projectId = "{project_id}" credentials = BasicCredentials(ak, sk, projectId) client = CfwClient.new_builder() \ .with_credentials(credentials) \ .with_region(CfwRegion.value_of("<YOUR REGION>")) \ .build() try: request = ExportLogsRequest() request.fw_instance_id = "{fw_instance_id}" listValuesFilters = [ "55637" ] listValuesFilters1 = [ "100.85.219.117" ] listFiltersbody = [ Filter( field="dst_ip", values=listValuesFilters1, operator="equal" ), Filter( field="src_port", values=listValuesFilters, operator="equal" ) ] request.body = ExportLogsRequestBody( time_zone="GMT%2B08:00", type="flow", log_type="internet", end_time=1751969212875, start_time=1751958412875, filters=listFiltersbody ) response = client.export_logs(request) print(response) except exceptions.ClientRequestException as e: print(e.status_code) print(e.request_id) print(e.error_code) print(e.error_msg) |
项目ID为a16df7cf1d094befa6bbc72cbf51e93a,防火墙ID为fcd04edd-428a-4631-bef5-46a924293cca,时间范围为1751958412875到1751969212875,过滤条件为目的IP为方向为100.85.219.117,目的端口为55637,导出互联网边界的流量日志
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 |
package main import ( "fmt" "github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic" cfw "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/cfw/v1" "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/cfw/v1/model" region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/cfw/v1/region" ) func main() { // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment ak := os.Getenv("CLOUD_SDK_AK") sk := os.Getenv("CLOUD_SDK_SK") projectId := "{project_id}" auth := basic.NewCredentialsBuilder(). WithAk(ak). WithSk(sk). WithProjectId(projectId). Build() client := cfw.NewCfwClient( cfw.CfwClientBuilder(). WithRegion(region.ValueOf("<YOUR REGION>")). WithCredential(auth). Build()) request := &model.ExportLogsRequest{} request.FwInstanceId = "{fw_instance_id}" var listValuesFilters = []string{ "55637", } var listValuesFilters1 = []string{ "100.85.219.117", } var listFiltersbody = []model.Filter{ { Field: "dst_ip", Values: &listValuesFilters1, Operator: model.GetFilterOperatorEnum().EQUAL, }, { Field: "src_port", Values: &listValuesFilters, Operator: model.GetFilterOperatorEnum().EQUAL, }, } timeZoneExportLogsRequestBody:= "GMT%2B08:00" request.Body = &model.ExportLogsRequestBody{ TimeZone: &timeZoneExportLogsRequestBody, Type: model.GetExportLogsRequestBodyTypeEnum().FLOW, LogType: model.GetExportLogsRequestBodyLogTypeEnum().INTERNET, EndTime: int64(1751969212875), StartTime: int64(1751958412875), Filters: &listFiltersbody, } response, err := client.ExportLogs(request) if err == nil { fmt.Printf("%+v\n", response) } else { fmt.Println(err) } } |
更多编程语言的SDK代码示例,请参见API Explorer的代码示例页签,可生成自动对应的SDK代码示例。
状态码
状态码 |
描述 |
---|---|
200 |
OK |
400 |
Bad Request |
错误码
请参见错误码。