Updated on 2026-02-05 GMT+08:00

Exporting Alerts

Function

This API is used to export alerts. If the field is of the object type, the content of the entire subobject is exported.

Calling Method

For details, see Calling APIs.

URI

POST /v1/{project_id}/workspaces/{workspace_id}/soc/alerts/export

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Definition

Project ID, which is used to specify the project that a resource belongs to. You can query the resources of a project by project ID. You can obtain the project ID from the API or console. Obtaining the Project ID

Constraints

N/A

Range

N/A

Default Value

N/A

workspace_id

Yes

String

Definition

Workspace ID.

Constraints

N/A

Range

N/A

Default Value

N/A

Request Parameters

Table 2 Request header parameters

Parameter

Mandatory

Type

Description

X-Auth-Token

Yes

String

Definition

User token. You can obtain it by calling the IAM API for obtaining a user token. The user token is the value of X-Subject-Token in the response header. Obtaining a User Token

Constraints

N/A

Range

N/A

Default Value

N/A

content-type

Yes

String

Definition

Content type.

  • application/json;charset=UTF-8: common API request type

Constraints

N/A

Range

  • application/json;charset=UTF-8

Default Value

N/A

Table 3 Request body parameters

Parameter

Mandatory

Type

Description

data_object_filters_form

No

DataobjectSearch object

Search criteria.

title

No

Array of strings

Exported field list.

Table 4 DataobjectSearch

Parameter

Mandatory

Type

Description

limit

No

Integer

The number of records on each page.

offset

No

Integer

Offset.

sort_by

No

String

Sorting field: create_time | update_time

order

No

String

Sorting order. Options: DESC and ASC.

from_date

No

String

Search start time, for example, 2023-02-20T00:00:00.000Z.

to_date

No

String

Search end time, for example, 2023-02-27T23:59:59.999Z.

condition

No

condition object

Search condition expression.

Table 5 condition

Parameter

Mandatory

Type

Description

conditions

No

Array of conditions objects

Expression list.

logics

No

Array of strings

Expression name list.

Table 6 conditions

Parameter

Mandatory

Type

Description

name

No

String

Expression name.

data

No

Array of strings

Expression content list.

Response Parameters

Status code: 200

Exported alert file.

Status code: 400

Table 7 Response body parameters

Parameter

Type

Description

code

String

Definition

Error code.

Range

N/A

message

String

Definition

Error description.

Range

N/A

Example Requests

Export 10 alerts that meet the conditions and specify the fields to be exported as ID, name, and severity.

https://{endpoint}/v1/{project_id}/workspaces/{workspace_id}/soc/alerts/export

{
  "title" : [ "id", "title", "severity" ],
  "data_object_filters_form" : {
    "limit" : 10,
    "offset" : 0,
    "sort_by" : "create_time",
    "order" : "DESC",
    "condition" : {
      "conditions" : [ {
        "name" : "severity",
        "data" : [ "severity", "=", "Medium" ]
      }, {
        "name" : "handle_status",
        "data" : [ "handle_status", "=", "Open" ]
      } ],
      "logics" : [ "severity", "and", "handle_status" ]
    },
    "from_date" : "2024-01-20T00:00:00.000Z+0800",
    "to_date" : "2024-01-26T23:59:59.999Z+0800"
  }
}

Example Responses

None

SDK Sample Code

The SDK sample code is as follows.

Export 10 alerts that meet the conditions and specify the fields to be exported as ID, name, and severity.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
package com.huaweicloud.sdk.test;

import com.huaweicloud.sdk.core.auth.ICredential;
import com.huaweicloud.sdk.core.auth.BasicCredentials;
import com.huaweicloud.sdk.core.exception.ConnectionException;
import com.huaweicloud.sdk.core.exception.RequestTimeoutException;
import com.huaweicloud.sdk.core.exception.ServiceResponseException;
import com.huaweicloud.sdk.secmaster.v1.region.SecMasterRegion;
import com.huaweicloud.sdk.secmaster.v1.*;
import com.huaweicloud.sdk.secmaster.v1.model.*;

import java.util.List;
import java.util.ArrayList;

public class ExportAlertsSolution {

    public static void main(String[] args) {
        // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
        // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
        String ak = System.getenv("CLOUD_SDK_AK");
        String sk = System.getenv("CLOUD_SDK_SK");
        String projectId = "{project_id}";

        ICredential auth = new BasicCredentials()
                .withProjectId(projectId)
                .withAk(ak)
                .withSk(sk);

        SecMasterClient client = SecMasterClient.newBuilder()
                .withCredential(auth)
                .withRegion(SecMasterRegion.valueOf("<YOUR REGION>"))
                .build();
        ExportAlertsRequest request = new ExportAlertsRequest();
        request.withWorkspaceId("{workspace_id}");
        ExportAlertsRequestBody body = new ExportAlertsRequestBody();
        List<String> listbodyTitle = new ArrayList<>();
        listbodyTitle.add("id");
        listbodyTitle.add("title");
        listbodyTitle.add("severity");
        List<String> listConditionLogics = new ArrayList<>();
        listConditionLogics.add("severity");
        listConditionLogics.add("and");
        listConditionLogics.add("handle_status");
        List<String> listConditionsData = new ArrayList<>();
        listConditionsData.add("handle_status");
        listConditionsData.add("=");
        listConditionsData.add("Open");
        List<String> listConditionsData1 = new ArrayList<>();
        listConditionsData1.add("severity");
        listConditionsData1.add("=");
        listConditionsData1.add("Medium");
        List<DataobjectSearchConditionConditions> listConditionConditions = new ArrayList<>();
        listConditionConditions.add(
            new DataobjectSearchConditionConditions()
                .withName("severity")
                .withData(listConditionsData1)
        );
        listConditionConditions.add(
            new DataobjectSearchConditionConditions()
                .withName("handle_status")
                .withData(listConditionsData)
        );
        DataobjectSearchCondition conditionDataObjectFiltersForm = new DataobjectSearchCondition();
        conditionDataObjectFiltersForm.withConditions(listConditionConditions)
            .withLogics(listConditionLogics);
        DataobjectSearch dataObjectFiltersFormbody = new DataobjectSearch();
        dataObjectFiltersFormbody.withLimit(10)
            .withOffset(0)
            .withSortBy("create_time")
            .withOrder(DataobjectSearch.OrderEnum.fromValue("DESC"))
            .withFromDate("2024-01-20T00:00:00.000Z+0800")
            .withToDate("2024-01-26T23:59:59.999Z+0800")
            .withCondition(conditionDataObjectFiltersForm);
        body.withTitle(listbodyTitle);
        body.withDataObjectFiltersForm(dataObjectFiltersFormbody);
        request.withBody(body);
        try {
            ExportAlertsResponse response = client.exportAlerts(request);
            System.out.println(response.toString());
        } catch (ConnectionException e) {
            e.printStackTrace();
        } catch (RequestTimeoutException e) {
            e.printStackTrace();
        } catch (ServiceResponseException e) {
            e.printStackTrace();
            System.out.println(e.getHttpStatusCode());
            System.out.println(e.getRequestId());
            System.out.println(e.getErrorCode());
            System.out.println(e.getErrorMsg());
        }
    }
}

Export 10 alerts that meet the conditions and specify the fields to be exported as ID, name, and severity.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
# coding: utf-8

import os
from huaweicloudsdkcore.auth.credentials import BasicCredentials
from huaweicloudsdksecmaster.v1.region.secmaster_region import SecMasterRegion
from huaweicloudsdkcore.exceptions import exceptions
from huaweicloudsdksecmaster.v1 import *

if __name__ == "__main__":
    # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak = os.environ["CLOUD_SDK_AK"]
    sk = os.environ["CLOUD_SDK_SK"]
    projectId = "{project_id}"

    credentials = BasicCredentials(ak, sk, projectId)

    client = SecMasterClient.new_builder() \
        .with_credentials(credentials) \
        .with_region(SecMasterRegion.value_of("<YOUR REGION>")) \
        .build()

    try:
        request = ExportAlertsRequest()
        request.workspace_id = "{workspace_id}"
        listTitlebody = [
            "id",
            "title",
            "severity"
        ]
        listLogicsCondition = [
            "severity",
            "and",
            "handle_status"
        ]
        listDataConditions = [
            "handle_status",
            "=",
            "Open"
        ]
        listDataConditions1 = [
            "severity",
            "=",
            "Medium"
        ]
        listConditionsCondition = [
            DataobjectSearchConditionConditions(
                name="severity",
                data=listDataConditions1
            ),
            DataobjectSearchConditionConditions(
                name="handle_status",
                data=listDataConditions
            )
        ]
        conditionDataObjectFiltersForm = DataobjectSearchCondition(
            conditions=listConditionsCondition,
            logics=listLogicsCondition
        )
        dataObjectFiltersFormbody = DataobjectSearch(
            limit=10,
            offset=0,
            sort_by="create_time",
            order="DESC",
            from_date="2024-01-20T00:00:00.000Z+0800",
            to_date="2024-01-26T23:59:59.999Z+0800",
            condition=conditionDataObjectFiltersForm
        )
        request.body = ExportAlertsRequestBody(
            title=listTitlebody,
            data_object_filters_form=dataObjectFiltersFormbody
        )
        response = client.export_alerts(request)
        print(response)
    except exceptions.ClientRequestException as e:
        print(e.status_code)
        print(e.request_id)
        print(e.error_code)
        print(e.error_msg)

Export 10 alerts that meet the conditions and specify the fields to be exported as ID, name, and severity.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
package main

import (
	"fmt"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic"
    secmaster "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/secmaster/v1"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/services/secmaster/v1/model"
    region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/secmaster/v1/region"
)

func main() {
    // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak := os.Getenv("CLOUD_SDK_AK")
    sk := os.Getenv("CLOUD_SDK_SK")
    projectId := "{project_id}"

    auth := basic.NewCredentialsBuilder().
        WithAk(ak).
        WithSk(sk).
        WithProjectId(projectId).
        Build()

    client := secmaster.NewSecMasterClient(
        secmaster.SecMasterClientBuilder().
            WithRegion(region.ValueOf("<YOUR REGION>")).
            WithCredential(auth).
            Build())

    request := &model.ExportAlertsRequest{}
	request.WorkspaceId = "{workspace_id}"
	var listTitlebody = []string{
        "id",
	    "title",
	    "severity",
    }
	var listLogicsCondition = []string{
        "severity",
	    "and",
	    "handle_status",
    }
	var listDataConditions = []string{
        "handle_status",
	    "=",
	    "Open",
    }
	var listDataConditions1 = []string{
        "severity",
	    "=",
	    "Medium",
    }
	nameConditions:= "severity"
	nameConditions1:= "handle_status"
	var listConditionsCondition = []model.DataobjectSearchConditionConditions{
        {
            Name: &nameConditions,
            Data: &listDataConditions1,
        },
        {
            Name: &nameConditions1,
            Data: &listDataConditions,
        },
    }
	conditionDataObjectFiltersForm := &model.DataobjectSearchCondition{
		Conditions: &listConditionsCondition,
		Logics: &listLogicsCondition,
	}
	limitDataObjectFiltersForm:= int32(10)
	offsetDataObjectFiltersForm:= int32(0)
	sortByDataObjectFiltersForm:= "create_time"
	orderDataObjectFiltersForm:= model.GetDataobjectSearchOrderEnum().DESC
	fromDateDataObjectFiltersForm:= "2024-01-20T00:00:00.000Z+0800"
	toDateDataObjectFiltersForm:= "2024-01-26T23:59:59.999Z+0800"
	dataObjectFiltersFormbody := &model.DataobjectSearch{
		Limit: &limitDataObjectFiltersForm,
		Offset: &offsetDataObjectFiltersForm,
		SortBy: &sortByDataObjectFiltersForm,
		Order: &orderDataObjectFiltersForm,
		FromDate: &fromDateDataObjectFiltersForm,
		ToDate: &toDateDataObjectFiltersForm,
		Condition: conditionDataObjectFiltersForm,
	}
	request.Body = &model.ExportAlertsRequestBody{
		Title: &listTitlebody,
		DataObjectFiltersForm: dataObjectFiltersFormbody,
	}
	response, err := client.ExportAlerts(request)
	if err == nil {
        fmt.Printf("%+v\n", response)
    } else {
        fmt.Println(err)
    }
}

For SDK sample code of more programming languages, see the Sample Code tab in API Explorer. SDK sample code can be automatically generated.

Status Codes

Status Code

Description

200

Exported alert file.

400

Response body for failed requests for exporting alerts.

Error Codes

See Error Codes.