Obtaining Findings Generated for an Access Preview
Function
This API is used to obtain the findings generated for an access preview.
Authorization Information
Each account root user has all the permissions required to call all APIs, but IAM users must be assigned the following required identity policy-based permissions. For details about the required permissions, see Permissions Policies and Supported Actions.
| Action | Access Level | Resource Type (*: required) | Condition Key | Alias | Dependencies |
|---|---|---|---|---|---|
| AccessAnalyzer:analyzer:listPreviewFindings | List | analyzer * | g:ResourceTag/<tag-key> | - | - |
URI
POST /v5/analyzers/{analyzer_id}/access-previews/{access_preview_id}/findings
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| analyzer_id | Yes | String | Definition: Unique identifier of an analyzer. You can call the ListAnalyzers API to obtain the analyzer ID. The response parameters of this API return an analyzer list. The id field of each analyzer object is the analyzer ID. Range: 1 to 36 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed. |
| access_preview_id | Yes | String | Definition: Unique identifier of an access preview. You can call the ListAccessPreviews API to retrieve all access previews created for a specified analyzer. The response of this API contains an access preview list. Each access preview summary object in the list contains a unique access_preview_id field, which is the preview access analysis ID. Range: 1 to 36 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed. |
Request Parameters
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| filters | No | Array of FindingFilter objects | Definition: A filter to match the returned findings. Constraints: N/A Range: Array length: 1 to 20. Default Value: N/A |
| limit | No | Integer | Definition: Maximum number of results on a page. Constraints: N/A Range: The value ranges from 1 to 200. Default Value: 100 |
| marker | No | String | Definition: Page marker. Constraints: N/A Range: The value contains 4 to 400 characters. Only letters, digits, and special characters (+/=-_) are allowed. Default Value: N/A |
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| criterion | Yes | Criterion object | Definition: Criteria in the filter. Constraints: Only one operator is allowed. Range: N/A Default Value: N/A |
| key | Yes | String | Definition: Filter key. Constraints: N/A Range: Default Value: N/A |
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| contains | No | Array of strings | Definition: Matching the "contains" operator in the filter. Constraints: N/A Range: Array length: 1 to 20. Default Value: N/A |
| eq | No | Array of strings | Definition: Matching the "eq" operator in the filter. Constraints: N/A Range: Array length: 1 to 20. Default Value: N/A |
| exists | No | Boolean | Definition: Matching the "exists" operator in the filter Constraints: N/A Range: N/A Default Value: N/A |
| neq | No | Array of strings | Definition: Matching the "neq" operator in the filter. Constraints: N/A Range: Array length: 1 to 20. Default Value: N/A |
Response Parameters
Status code: 200
| Parameter | Type | Description |
|---|---|---|
| findings | Array of PreviewFinding objects | Definition: List of findings generated by an access preview. Range: N/A |
| page_info | PageInfo object | Definition: Page information. Range: N/A |
| Parameter | Type | Description |
|---|---|---|
| action | Array of strings | Definition: Action that can be used by external principals. Range: N/A |
| change_type | String | Definition: Finding change. Range: |
| condition | Array of FindingCondition objects | Definition: Condition that generates findings in the policy statement. Range: N/A |
| created_at | String | Definition: Time when the findings were generated for an access preview. The UTC+0 time zone is used. The format is yyyy-MM-ddTHH:mm:ss.SSSZ, for example, 2023-09-07T07:51:10.502Z. Range: N/A |
| existing_finding_id | String | Definition: Unique identifier of a finding. Range: 1 to 36 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed. |
| existing_finding_status | String | Definition: Finding status. Range: |
| id | String | Definition: Unique identifier of a finding. Range: 1 to 36 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed. |
| is_public | Boolean | Definition: Whether the policy that generates findings allows public access to resources. Range: N/A |
| principal | FindingPrincipal object | Definition: External principal that accesses resources in the trusted zone. Range: N/A |
| resource | String | Definition: Unique identifier of a resource. Range: N/A |
| resource_owner_account | String | Definition: ID of the account that owns resources. Range: 1 to 36 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed. |
| resource_type | String | Definition: Type of a resource. Range: |
| sources | Array of strings | Definition: Source of findings. Range: |
| status | String | Definition: Status after the change. Range: |
| Parameter | Type | Description |
|---|---|---|
| key | String | Definition: Identifier or name of the condition key. Range: N/A |
| value | String | Definition: Value of the condition key. Range: N/A |
| Parameter | Type | Description |
|---|---|---|
| identifier | String | Definition: Identifier of an external principal. Range: N/A |
| type | String | Definition: Type of an external principal. Range: |
| Parameter | Type | Description |
|---|---|---|
| current_count | Integer | Definition: Number of items on the current page. Range: N/A |
| next_marker | String | Definition: If present, it indicates that the available output is more than the output contained in the current response. Use this value in the marker request parameter in a subsequent call to the operation to get the next part of the output. You should repeat this operation until the next_marker response returns null. Range: Only letters, digits, plus signs (+), slashes (/), equal signs (=), underscores (_), and hyphens (-) are allowed. |
Example Requests
Obtaining findings generated for an access preview
POST https://{hostname}/v5/analyzers/{analyzer_id}/access-previews/{access_preview_id}/findings
{
"filters" : [ {
"criterion" : {
"eq" : [ "iam:agency" ]
},
"key" : "resource_type"
} ]
} Example Responses
Status code: 200
OK
{
"findings" : [ {
"action" : [ "sts::setSourceIdentity", "sts::tagSession", "sts:agencies:assume" ],
"change_type" : "new",
"condition" : [ {
"key" : "g:PrincipalOrgId",
"value" : "org_id"
} ],
"created_at" : "2023-09-07T07:26:23.440Z",
"existing_finding_status" : null,
"existing_finding_id" : null,
"is_public" : false,
"id" : "{finding_id}",
"principal" : {
"identifier" : "{domain_id}",
"type" : "account"
},
"resource" : "iam::{domain_id}:agency:{agency_name}",
"resource_owner_account" : "{domain_id}",
"resource_type" : "iam:agency",
"status" : "active"
} ],
"page_info" : {
"current_count" : 1,
"next_marker" : null
}
} Status Codes
| Status Code | Description |
|---|---|
| 200 | OK |
Error Codes
See Error Codes.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot