查询访问控制日志
功能介绍
查询访问控制日志
调用方法
请参见如何调用API。
URI
GET /v1/{project_id}/cfw/logs/access-control
参数 |
是否必选 |
参数类型 |
描述 |
---|---|---|---|
project_id |
是 |
String |
租户项目id |
参数 |
是否必选 |
参数类型 |
描述 |
---|---|---|---|
fw_instance_id |
是 |
String |
防火墙实例id,创建云防火墙后用于标志防火墙由系统自动生成的标志id,可通过调用查询防火墙实例接口获得。具体可参考APIExlorer和帮助中心FAQ。 |
rule_id |
否 |
String |
规则ID |
start_time |
是 |
Long |
开始时间 |
end_time |
是 |
Long |
结束时间 |
src_ip |
否 |
String |
源IP |
src_port |
否 |
Integer |
源端口 |
dst_ip |
否 |
String |
目的IP |
dst_port |
否 |
Integer |
目的端口 |
protocol |
否 |
String |
协议 |
app |
否 |
String |
应用协议 |
log_id |
否 |
String |
文档ID,第一页为空,其他页不为空 |
next_date |
否 |
Integer |
日期,第一页为空,其他页不为空 |
offset |
否 |
Integer |
偏移量:指定返回记录的开始位置,必须为数字,取值范围为大于或等于0,默认0 |
limit |
是 |
Integer |
每页显示个数,范围为1-1024 |
log_type |
否 |
String |
日志类型 枚举值:
|
enterprise_project_id |
否 |
String |
企业项目id,用户支持企业项目后,由企业项目生成的id。 |
dst_host |
否 |
String |
目标主机 |
rule_name |
否 |
String |
规则名称 |
action |
否 |
String |
动作0:permit,1:deny |
src_region_name |
否 |
String |
源region名称 |
dst_region_name |
否 |
String |
目的region名称 |
请求参数
参数 |
是否必选 |
参数类型 |
描述 |
---|---|---|---|
X-Auth-Token |
是 |
String |
用户Token。 通过调用IAM服务获取用户Token接口获取(响应消息头中X-Subject-Token的值) |
响应参数
状态码: 200
参数 |
参数类型 |
描述 |
---|---|---|
data |
data object |
查询访问控制日志返回数据 |
参数 |
参数类型 |
描述 |
---|---|---|
total |
Integer |
返回数量 |
limit |
Integer |
每页显示个数,范围为1-1024 |
records |
Array of records objects |
记录 |
参数 |
参数类型 |
描述 |
---|---|---|
action |
String |
动作0:permit,1:deny |
rule_name |
String |
规则名称 |
rule_id |
String |
规则ID |
hit_time |
Long |
命中时间 |
src_region_id |
String |
源区域id |
src_region_name |
String |
源区域name |
dst_region_id |
String |
目的区域id |
dst_region_name |
String |
目的区域name |
log_id |
String |
文档ID |
src_ip |
String |
源IP |
src_port |
Integer |
源端口 |
dst_ip |
String |
目的IP |
dst_port |
Integer |
目的端口 |
protocol |
String |
协议类型:TCP为6,UDP为17,ICMP为1,ICMPV6为58,ANY为-1,手动类型不为空,自动类型为空 |
app |
String |
应用协议 |
dst_host |
String |
目标主机 |
状态码: 400
参数 |
参数类型 |
描述 |
---|---|---|
error_code |
String |
错误码 最小长度:8 最大长度:36 |
error_msg |
String |
错误描述 最小长度:2 最大长度:512 |
请求示例
查询项目id为9d80d070b6d44942af73c9c3d38e0429,防火墙id为2af58b7c-893c-4453-a984-bdd9b1bd6318,开始时间为1664159069544,结束时间为1664162669544,初始位置为0的第一页的数据
https://{Endpoint}/v1/9d80d070b6d44942af73c9c3d38e0429/cfw/logs/access-control?fw_instance_id=2af58b7c-893c-4453-a984-bdd9b1bd6318&start_time=1664159069544&end_time=1664162669544&limit=10
响应示例
状态码: 200
OK
{ "data" : { "limit" : 10, "records" : [ { "action" : "deny", "app" : "PING", "dst_ip" : "100.85.216.211", "dst_port" : 59, "hit_time" : 1664164255000, "log_id" : "46032", "protocol" : "ICMP: ECHO_REQUEST", "rule_id" : "c755be1c-4b92-4ae7-a15e-c2d02b152538", "rule_name" : "eip_ipv4_w_n_default_deny", "src_ip" : "100.95.148.49", "src_port" : 24954 } ], "total" : 1 } }
状态码: 400
Bad Request
{ "error_code" : "CFW.00500002", "error_msg" : "时间间距错误" }
SDK代码示例
SDK代码示例如下。
Java
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 |
package com.huaweicloud.sdk.test; import com.huaweicloud.sdk.core.auth.ICredential; import com.huaweicloud.sdk.core.auth.BasicCredentials; import com.huaweicloud.sdk.core.exception.ConnectionException; import com.huaweicloud.sdk.core.exception.RequestTimeoutException; import com.huaweicloud.sdk.core.exception.ServiceResponseException; import com.huaweicloud.sdk.cfw.v1.region.CfwRegion; import com.huaweicloud.sdk.cfw.v1.*; import com.huaweicloud.sdk.cfw.v1.model.*; public class ListAccessControlLogsSolution { public static void main(String[] args) { // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment String ak = System.getenv("CLOUD_SDK_AK"); String sk = System.getenv("CLOUD_SDK_SK"); ICredential auth = new BasicCredentials() .withAk(ak) .withSk(sk); CfwClient client = CfwClient.newBuilder() .withCredential(auth) .withRegion(CfwRegion.valueOf("<YOUR REGION>")) .build(); ListAccessControlLogsRequest request = new ListAccessControlLogsRequest(); request.withFwInstanceId("<fw_instance_id>"); request.withRuleId("<rule_id>"); request.withStartTime(<start_time>L); request.withEndTime(<end_time>L); request.withSrcIp("<src_ip>"); request.withSrcPort(<src_port>); request.withDstIp("<dst_ip>"); request.withDstPort(<dst_port>); request.withProtocol("<protocol>"); request.withApp("<app>"); request.withLogId("<log_id>"); request.withNextDate(<next_date>); request.withOffset(<offset>); request.withLimit(<limit>); request.withLogType(ListAccessControlLogsRequest.LogTypeEnum.fromValue("<log_type>")); request.withEnterpriseProjectId("<enterprise_project_id>"); request.withDstHost("<dst_host>"); request.withRuleName("<rule_name>"); request.withAction("<action>"); try { ListAccessControlLogsResponse response = client.listAccessControlLogs(request); System.out.println(response.toString()); } catch (ConnectionException e) { e.printStackTrace(); } catch (RequestTimeoutException e) { e.printStackTrace(); } catch (ServiceResponseException e) { e.printStackTrace(); System.out.println(e.getHttpStatusCode()); System.out.println(e.getRequestId()); System.out.println(e.getErrorCode()); System.out.println(e.getErrorMsg()); } } } |
Python
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 |
# coding: utf-8 from huaweicloudsdkcore.auth.credentials import BasicCredentials from huaweicloudsdkcfw.v1.region.cfw_region import CfwRegion from huaweicloudsdkcore.exceptions import exceptions from huaweicloudsdkcfw.v1 import * if __name__ == "__main__": # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment ak = __import__('os').getenv("CLOUD_SDK_AK") sk = __import__('os').getenv("CLOUD_SDK_SK") credentials = BasicCredentials(ak, sk) \ client = CfwClient.new_builder() \ .with_credentials(credentials) \ .with_region(CfwRegion.value_of("<YOUR REGION>")) \ .build() try: request = ListAccessControlLogsRequest() request.fw_instance_id = "<fw_instance_id>" request.rule_id = "<rule_id>" request.start_time = <start_time> request.end_time = <end_time> request.src_ip = "<src_ip>" request.src_port = <src_port> request.dst_ip = "<dst_ip>" request.dst_port = <dst_port> request.protocol = "<protocol>" request.app = "<app>" request.log_id = "<log_id>" request.next_date = <next_date> request.offset = <offset> request.limit = <limit> request.log_type = "<log_type>" request.enterprise_project_id = "<enterprise_project_id>" request.dst_host = "<dst_host>" request.rule_name = "<rule_name>" request.action = "<action>" response = client.list_access_control_logs(request) print(response) except exceptions.ClientRequestException as e: print(e.status_code) print(e.request_id) print(e.error_code) print(e.error_msg) |
Go
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 |
package main import ( "fmt" "github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic" cfw "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/cfw/v1" "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/cfw/v1/model" region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/cfw/v1/region" ) func main() { // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment ak := os.Getenv("CLOUD_SDK_AK") sk := os.Getenv("CLOUD_SDK_SK") auth := basic.NewCredentialsBuilder(). WithAk(ak). WithSk(sk). Build() client := cfw.NewCfwClient( cfw.CfwClientBuilder(). WithRegion(region.ValueOf("<YOUR REGION>")). WithCredential(auth). Build()) request := &model.ListAccessControlLogsRequest{} request.FwInstanceId = "<fw_instance_id>" ruleIdRequest:= "<rule_id>" request.RuleId = &ruleIdRequest request.StartTime = int64(<start_time>) request.EndTime = int64(<end_time>) srcIpRequest:= "<src_ip>" request.SrcIp = &srcIpRequest srcPortRequest:= int32(<src_port>) request.SrcPort = &srcPortRequest dstIpRequest:= "<dst_ip>" request.DstIp = &dstIpRequest dstPortRequest:= int32(<dst_port>) request.DstPort = &dstPortRequest protocolRequest:= "<protocol>" request.Protocol = &protocolRequest appRequest:= "<app>" request.App = &appRequest logIdRequest:= "<log_id>" request.LogId = &logIdRequest nextDateRequest:= int32(<next_date>) request.NextDate = &nextDateRequest offsetRequest:= int32(<offset>) request.Offset = &offsetRequest request.Limit = int32(<limit>) logTypeRequest:= model.GetListAccessControlLogsRequestLogTypeEnum().<LOG_TYPE> request.LogType = &logTypeRequest enterpriseProjectIdRequest:= "<enterprise_project_id>" request.EnterpriseProjectId = &enterpriseProjectIdRequest dstHostRequest:= "<dst_host>" request.DstHost = &dstHostRequest ruleNameRequest:= "<rule_name>" request.RuleName = &ruleNameRequest actionRequest:= "<action>" request.Action = &actionRequest response, err := client.ListAccessControlLogs(request) if err == nil { fmt.Printf("%+v\n", response) } else { fmt.Println(err) } } |
更多
更多编程语言的SDK代码示例,请参见API Explorer的代码示例页签,可生成自动对应的SDK代码示例。
状态码
状态码 |
描述 |
---|---|
200 |
OK |
400 |
Bad Request |
401 |
Unauthorized |
403 |
Forbidden |
404 |
Not Found |
500 |
Internal Server Error |
错误码
请参见错误码。