Retrieving a List of Findings Generated by the Specified Analyzer
Function
This API is used to retrieve a list of findings generated by the specified analyzer.
Authorization Information
Each account root user has all the permissions required to call all APIs, but IAM users must be assigned the following required identity policy-based permissions. For details about the required permissions, see Permissions Policies and Supported Actions.
| Action | Access Level | Resource Type (*: required) | Condition Key | Alias | Dependencies |
|---|---|---|---|---|---|
| AccessAnalyzer:analyzer:listFindings | List | analyzer * | g:ResourceTag/<tag-key> | - | - |
URI
POST /v5/analyzers/{analyzer_id}/findings
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| analyzer_id | Yes | String | Definition: Unique identifier of an analyzer. You can call the ListAnalyzers API to obtain the analyzer ID. The response parameters of this API return an analyzer list. The id field of each analyzer object is the analyzer ID. Range: 1 to 36 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed. |
Request Parameters
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| filters | No | Array of FindingFilter objects | Definition: A filter to match the returned findings. Constraints: N/A Range: Array length: 1 to 20. Default Value: N/A |
| limit | No | Integer | Definition: Maximum number of results on a page. Constraints: N/A Range: The value ranges from 1 to 200. Default Value: 100 |
| marker | No | String | Definition: Page marker. Constraints: N/A Range: The value contains 4 to 400 characters. Only letters, digits, and special characters (+/=-_) are allowed. Default Value: N/A |
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| criterion | Yes | Criterion object | Definition: Criteria in the filter. Constraints: Only one operator is allowed. Range: N/A Default Value: N/A |
| key | Yes | String | Definition: Filter key. Constraints: N/A Range: Default Value: N/A |
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| contains | No | Array of strings | Definition: Matching the "contains" operator in the filter. Constraints: N/A Range: Array length: 1 to 20. Default Value: N/A |
| eq | No | Array of strings | Definition: Matching the "eq" operator in the filter. Constraints: N/A Range: Array length: 1 to 20. Default Value: N/A |
| exists | No | Boolean | Definition: Matching the "exists" operator in the filter Constraints: N/A Range: N/A Default Value: N/A |
| neq | No | Array of strings | Definition: Matching the "neq" operator in the filter. Constraints: N/A Range: Array length: 1 to 20. Default Value: N/A |
Response Parameters
Status code: 200
| Parameter | Type | Description |
|---|---|---|
| findings | Array of FindingSummary objects | Definition: List of findings. Range: N/A |
| page_info | PageInfo object | Definition: Page information. Range: N/A |
| Parameter | Type | Description |
|---|---|---|
| action | Array of strings | Definition: Action that can be used by external principals. Range: N/A |
| analyzed_at | String | Definition: Time when resources were analyzed. The UTC+0 time zone is used. The format is yyyy-MM-ddTHH:mm:ss.SSSZ, for example, 2023-09-07T07:51:10.502Z. Range: N/A |
| condition | Array of FindingCondition objects | Definition: Condition that generates findings in the policy statement. Range: N/A |
| created_at | String | Definition: Time when the findings were generated. The UTC+0 time zone is used. The format is yyyy-MM-ddTHH:mm:ss.SSSZ, for example, 2023-09-07T07:51:10.502Z. Range: N/A |
| finding_type | String | Definition: Finding type. Range:
|
| id | String | Definition: Unique identifier of a finding. Range: 1 to 36 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed. |
| is_public | Boolean | Definition: Whether the policy that generates findings allows public access to resources. Range: N/A |
| principal | FindingPrincipal object | Definition: External principal that accesses resources in the trusted zone. Range: N/A |
| resource | String | Definition: Unique identifier of a resource. Range: N/A |
| resource_id | String | Definition: Unique identifier of a resource. Range: 1 to 36 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed. |
| resource_owner_account | String | Definition: ID of the account that owns resources. Range: 1 to 36 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed. |
| resource_project_id | String | Definition: Project ID of a resource. Range: A maximum of 36 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed. |
| resource_type | String | Definition: Type of a resource. Range: |
| sources | Array of strings | Definition: Source of findings, indicating how to grant access that generates the findings. Range: |
| status | String | Definition: Finding status. Range: |
| updated_at | String | Definition: Time when the findings were updated. The UTC+0 time zone is used. The format is yyyy-MM-ddTHH:mm:ss.SSSZ, for example, 2023-09-07T07:51:10.502Z. Range: N/A |
| Parameter | Type | Description |
|---|---|---|
| key | String | Definition: Identifier or name of the condition key. Range: N/A |
| value | String | Definition: Value of the condition key. Range: N/A |
| Parameter | Type | Description |
|---|---|---|
| identifier | String | Definition: Identifier of an external principal. Range: N/A |
| type | String | Definition: Type of an external principal. Range: |
| Parameter | Type | Description |
|---|---|---|
| current_count | Integer | Definition: Number of items on the current page. Range: N/A |
| next_marker | String | Definition: If present, it indicates that the available output is more than the output contained in the current response. Use this value in the marker request parameter in a subsequent call to the operation to get the next part of the output. You should repeat this operation until the next_marker response returns null. Range: Only letters, digits, plus signs (+), slashes (/), equal signs (=), underscores (_), and hyphens (-) are allowed. |
Example Requests
Retrieving a list of findings generated by the specified analyzer
POST https://{hostname}/v5/analyzers/{analyzer_id}/findings
{
"filters" : [ {
"criterion" : {
"eq" : [ "iam:agency" ]
},
"key" : "resource_type"
} ],
"limit" : 100,
"marker" : "{marker_string}"
} Example Responses
Status code: 200
OK
{
"findings" : [ {
"action" : [ "sts:agencies:assume" ],
"analyzed_at" : "2023-09-07T08:04:41.698Z",
"condition" : [ {
"key" : "g:PrincipalOrgId",
"value" : "org_id"
} ],
"created_at" : "2023-09-07T08:04:41.698Z",
"id" : "{finding_id}",
"is_public" : false,
"principal" : {
"identifier" : "{domain_id}",
"type" : "account"
},
"resource" : "iam::{domain_id}:agency:{agency_name}",
"resource_owner_account" : "{domain_id}",
"resource_id" : "{agency_id}",
"resource_type" : "iam:agency",
"status" : "active",
"updated_at" : "2023-09-07T08:04:41.698Z"
} ],
"page_info" : {
"current_count" : 1,
"next_marker" : null
}
} Status Codes
| Status Code | Description |
|---|---|
| 200 | OK |
Error Codes
See Error Codes.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot