
# 创建分析脚本 - CreateAnalysisScript
#### 功能介绍
创建分析脚本
#### 调用方法
请参见[如何调用API](https://support.huaweicloud.com/api-secmaster/secmaster_03_0008.html)。
#### 授权信息
账号具备所有API的调用权限，如果使用账号下的IAM用户调用当前API，该IAM用户需具备调用API所需的权限，具体权限要求请参见[权限和授权项](https://support.huaweicloud.com/api-secmaster/secmaster_03_0023.html)。
#### URI
POST /v2/{project_id}/workspaces/{workspace_id}/siem/analysis-scripts
表1路径参数 
| 参数           | 是否必选 | 参数类型   | 描述                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
|:---|:---|:---|:---|
| project_id   | 是    | String | **参数解释**： 项目ID，用于明确项目归属，配置后可通过该ID查询项目下资产，可以通过调用API获取，也可以从控制台获取。[获取项目ID](https://support.huaweicloud.com/api-secmaster/secmaster_03_0014.html) **约束限制**： 不涉及 **取值范围**： 不涉及 **默认取值**： 不涉及 |
| workspace_id | 是    | String | **参数解释**： 工作空间ID **约束限制**： 不涉及 **取值范围**： 不涉及 **默认取值**： 不涉及                                                                                                                              |
   
#### 请求参数
表2请求Header参数 
| 参数           | 是否必选 | 参数类型   | 描述                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
|:---|:---|:---|:---|
| X-Auth-Token | 是    | String | **参数解释**： 用户Token，通过调用IAM服务获取用户Token接口获取（响应消息头中X-Subject-Token的值）。[获取用户Token](https://support.huaweicloud.com/api-secmaster/secmaster_03_0010.html) **约束限制**： 不涉及 **取值范围**： 不涉及 **默认取值**： 不涉及 |
   
表3请求Body参数 
| 参数                  | 是否必选 | 参数类型                                                                                       | 描述                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
|:---|:---|:---|:---|
| script_name         | 是    | String                                                                                     | 脚本名称                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| category            | 是    | String                                                                                     | **参数解释**： 脚本分类 - RETRIEVE 检索   - ANALYSIS 分析    **约束限制**： 不涉及 **取值范围**： - RETRIEVE   - ANALYSIS    **默认取值**： 不涉及                               |
| directory           | 否    | String                                                                                     | 脚本目录分组名称，长度在1到256个字符之间。                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| description         | 否    | String                                                                                     | 脚本的相关描述信息，长度在1到1024个字符之间。                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| script_type         | 是    | String                                                                                     | **参数解释**： 分析脚本类型 - SEC_MASTER_SQL 安全云脑SQL   - RETRIEVE_SQL 检索SQL    **约束限制**： 不涉及 **取值范围**： - SEC_MASTER_SQL   - RETRIEVE_SQL    **默认取值**： 不涉及 |
| retrieve_table_id   | 否    | String                                                                                     | UUID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| retrieve_table_name | 否    | String                                                                                     | 表名                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| script              | 是    | String                                                                                     | 脚本内容，长度在1到10240个字符之间。                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| owner               | 否    | String                                                                                     | Iam用户ID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| script_params       | 是    | Array of [AnalysisScriptParam] objects | 分析脚本参数列表                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
   
 表4AnalysisScriptParam 
| 参数    | 是否必选 | 参数类型   | 描述      |
|:---|:---|:---|:---|
| key   | 否    | String | 键 key   |
| value | 否    | String | 值 value |
   
#### 响应参数
**状态码：200**
表5响应Body参数 
| 参数                | 参数类型                                                                                        | 描述                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
|:---|:---|:---|
| script_id         | String                                                                                      | UUID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| project_id        | String                                                                                      | 项目ID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| workspace_id      | String                                                                                      | 工作空间ID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| script_name       | String                                                                                      | 脚本名称                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| category          | String                                                                                      | **参数解释**： 脚本分类 - RETRIEVE 检索   - ANALYSIS 分析    **约束限制**： 不涉及 **取值范围**： - RETRIEVE   - ANALYSIS    **默认取值**： 不涉及                               |
| directory         | String                                                                                      | 脚本目录分组名称，长度在1到256个字符之间。                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| description       | String                                                                                      | 脚本的相关描述信息，长度在1到1024个字符之间。                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| script_type       | String                                                                                      | **参数解释**： 分析脚本类型 - SEC_MASTER_SQL 安全云脑SQL   - RETRIEVE_SQL 检索SQL    **约束限制**： 不涉及 **取值范围**： - SEC_MASTER_SQL   - RETRIEVE_SQL    **默认取值**： 不涉及 |
| retrieve_table_id | String                                                                                      | UUID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| script            | String                                                                                      | 脚本内容，长度在1到10240个字符之间。                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| owner             | String                                                                                      | Iam用户ID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| script_params     | Array of [AnalysisScriptParam] objects | 分析脚本参数列表                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| create_by         | String                                                                                      | Iam用户ID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| create_time       | Integer                                                                                     | 毫秒时间戳                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| update_by         | String                                                                                      | Iam用户ID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| update_time       | Integer                                                                                     | 毫秒时间戳                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
   
 表6AnalysisScriptParam 
| 参数    | 参数类型   | 描述      |
|:---|:---|:---|
| key   | String | 键 key   |
| value | String | 值 value |
   
**状态码：400**
表7响应Body参数 
| 参数         | 参数类型   | 描述                                                                                                                                                                                                                                                                                                                                               |
|:---|:---|:---|
| error_code | String | **参数解释**： 错误码 **约束限制**： 不涉及 **取值范围**： 不涉及 **默认取值**： 不涉及  |
| error_msg  | String | **参数解释**： 错误描述 **约束限制**： 不涉及 **取值范围**： 不涉及 **默认取值**： 不涉及 |
   
#### 请求示例
创建分析脚本
```
https://{endpoint}/v2/{project_id}/workspaces/{workspace_id}/siem/analysis-scripts
{
  "retrieve_table_id" : "96c0b2f1-57db-4ba6-8039-24ab39717aaf",
  "script_name" : "test_script",
  "directory" : "",
  "description" : "",
  "script" : "* | select *",
  "owner" : "",
  "script_params" : [ ],
  "script_type" : "RETRIEVE_SQL",
  "category" : 1
}
```
#### 响应示例
**状态码：200**
成功
```
{ }
```
#### SDK代码示例
SDK代码示例如下。
- [Java]
  创建分析脚本
  ```
  package com.huaweicloud.sdk.test;
  import com.huaweicloud.sdk.core.auth.ICredential;
  import com.huaweicloud.sdk.core.auth.BasicCredentials;
  import com.huaweicloud.sdk.core.exception.ConnectionException;
  import com.huaweicloud.sdk.core.exception.RequestTimeoutException;
  import com.huaweicloud.sdk.core.exception.ServiceResponseException;
  import com.huaweicloud.sdk.secmaster.v2.region.SecMasterRegion;
  import com.huaweicloud.sdk.secmaster.v2.*;
  import com.huaweicloud.sdk.secmaster.v2.model.*;
  import java.util.List;
  import java.util.ArrayList;
  public class CreateAnalysisScriptSolution {
      public static void main(String[] args) {
          // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
          // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
          String ak = System.getenv("CLOUD_SDK_AK");
          String sk = System.getenv("CLOUD_SDK_SK");
          String projectId = "{project_id}";
          ICredential auth = new BasicCredentials()
                  .withProjectId(projectId)
                  .withAk(ak)
                  .withSk(sk);
          SecMasterClient client = SecMasterClient.newBuilder()
                  .withCredential(auth)
                  .withRegion(SecMasterRegion.valueOf("<YOUR REGION>"))
                  .build();
          CreateAnalysisScriptRequest request = new CreateAnalysisScriptRequest();
          request.withWorkspaceId("{workspace_id}");
          CreateAnalysisScriptRequestBody body = new CreateAnalysisScriptRequestBody();
          body.withOwner("");
          body.withScript("* | select *");
          body.withRetrieveTableId("96c0b2f1-57db-4ba6-8039-24ab39717aaf");
          body.withScriptType(CreateAnalysisScriptRequestBody.ScriptTypeEnum.fromValue("RETRIEVE_SQL"));
          body.withDescription("");
          body.withDirectory("");
          body.withCategory(CreateAnalysisScriptRequestBody.CategoryEnum.fromValue("1"));
          body.withScriptName("test_script");
          request.withBody(body);
          try {
              CreateAnalysisScriptResponse response = client.createAnalysisScript(request);
              System.out.println(response.toString());
          } catch (ConnectionException e) {
              e.printStackTrace();
          } catch (RequestTimeoutException e) {
              e.printStackTrace();
          } catch (ServiceResponseException e) {
              e.printStackTrace();
              System.out.println(e.getHttpStatusCode());
              System.out.println(e.getRequestId());
              System.out.println(e.getErrorCode());
              System.out.println(e.getErrorMsg());
          }
      }
  }
  ```
- [Python]
  创建分析脚本
  ```
  # coding: utf-8
  import os
  from huaweicloudsdkcore.auth.credentials import BasicCredentials
  from huaweicloudsdksecmaster.v2.region.secmaster_region import SecMasterRegion
  from huaweicloudsdkcore.exceptions import exceptions
  from huaweicloudsdksecmaster.v2 import *
  if __name__ == "__main__":
      # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
      # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
      ak = os.environ["CLOUD_SDK_AK"]
      sk = os.environ["CLOUD_SDK_SK"]
      projectId = "{project_id}"
      credentials = BasicCredentials(ak, sk, projectId)
      client = SecMasterClient.new_builder() \
          .with_credentials(credentials) \
          .with_region(SecMasterRegion.value_of("<YOUR REGION>")) \
          .build()
      try:
          request = CreateAnalysisScriptRequest()
          request.workspace_id = "{workspace_id}"
          request.body = CreateAnalysisScriptRequestBody(
              owner="",
              script="* | select *",
              retrieve_table_id="96c0b2f1-57db-4ba6-8039-24ab39717aaf",
              script_type="RETRIEVE_SQL",
              description="",
              directory="",
              category="1",
              script_name="test_script"
          )
          response = client.create_analysis_script(request)
          print(response)
      except exceptions.ClientRequestException as e:
          print(e.status_code)
          print(e.request_id)
          print(e.error_code)
          print(e.error_msg)
  ```
- [Go]
  创建分析脚本
  ```
  package main
  import (
  "fmt"
  "github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic"
      secmaster "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/secmaster/v2"
  "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/secmaster/v2/model"
      region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/secmaster/v2/region"
  )
  func main() {
      // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
      // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
      ak := os.Getenv("CLOUD_SDK_AK")
      sk := os.Getenv("CLOUD_SDK_SK")
      projectId := "{project_id}"
      auth, err := basic.NewCredentialsBuilder().
          WithAk(ak).
          WithSk(sk).
          WithProjectId(projectId).
          SafeBuild()
      if err != nil {
          fmt.Println(err)
          return
      }
      hcClient, err := secmaster.SecMasterClientBuilder().
           WithRegion(region.ValueOf("<YOUR REGION>")).
           WithCredential(auth).
           SafeBuild()
      if err != nil {
          fmt.Println(err)
          return
      }
      client := secmaster.NewSecMasterClient(hcClient)
      request := &model.CreateAnalysisScriptRequest{}
  request.WorkspaceId = "{workspace_id}"
  ownerCreateAnalysisScriptRequestBody:= ""
  retrieveTableIdCreateAnalysisScriptRequestBody:= "96c0b2f1-57db-4ba6-8039-24ab39717aaf"
  scriptTypeScriptType:= model.GetAnalysisScriptTypeScriptTypeEnum().RETRIEVE_SQL
  descriptionCreateAnalysisScriptRequestBody:= ""
  directoryCreateAnalysisScriptRequestBody:= ""
  categoryCategory:= model.GetScriptCategoryCategoryEnum().E_1
  request.Body = &model.CreateAnalysisScriptRequestBody{
  Owner: &ownerCreateAnalysisScriptRequestBody,
  Script: "* | select *",
  RetrieveTableId: &retrieveTableIdCreateAnalysisScriptRequestBody,
  ScriptType: &scriptTypeScriptType,
  Description: &descriptionCreateAnalysisScriptRequestBody,
  Directory: &directoryCreateAnalysisScriptRequestBody,
  Category: &categoryCategory,
  ScriptName: "test_script",
  }
  response, err := client.CreateAnalysisScript(request)
  if err == nil {
          fmt.Printf("%+v\n", response)
      } else {
          fmt.Println(err)
      }
  }
  ```
- [更多]
  更多编程语言的SDK代码示例，请参见[API Explorer](https://console.huaweicloud.com/apiexplorer/#/openapi/SecMaster/sdk?api=CreateAnalysisScript&version=v2)的代码示例页签，可生成自动对应的SDK代码示例。
#### 状态码
| 状态码 | 描述   |
|:---|:---|
| 200 | 成功   |
| 400 | 错误响应 |
   
#### 错误码
请参见[错误码](https://support.huaweicloud.com/api-secmaster/ErrorCode.html)。
