文档首页/ 安全云脑 SecMaster/ API参考/ API/ 基线检查/ 搜索基线检查结果列表
更新时间:2024-12-13 GMT+08:00

搜索基线检查结果列表

功能介绍

搜索基线检查结果列表

调用方法

请参见如何调用API

URI

POST /v2/{project_id}/workspaces/{workspace_id}/sa/baseline/search

表1 路径参数

参数

是否必选

参数类型

描述

project_id

String

项目id

workspace_id

String

工作空间id

请求参数

表2 请求Header参数

参数

是否必选

参数类型

描述

X-Auth-Token

String

用户token

X-Language

String

语言,参考值:zh-CN、en-US

content-type

String

内容类型

表3 请求Body参数

参数

是否必选

参数类型

描述

limit

Integer

分页大小

offset

Integer

偏移量,表示查询该偏移量后面的记录

sort_by

String

排序关键字

order

String

降序或升序, DESC|ESC

from_date

String

起始时间,格式ISO8601:YYYY-MM-DDTHH:mm:ss.ms+timezone。时区信息为事件发生时区,无法解析时区的时间,默认时区填东八区

to_date

String

截止时间,格式ISO8601:YYYY-MM-DDTHH:mm:ss.ms+timezone。时区信息为事件发生时区,无法解析时区的时间,默认时区填东八区

condition

Object

搜索条件表达式

响应参数

状态码: 200

表4 响应Body参数

参数

参数类型

描述

code

String

错误码

total

Integer

查询结果总数

size

Integer

分页大小

page

Integer

偏移量

success

Boolean

是否成功

data

Array of strings

查询结果列表

状态码: 400

表5 响应Body参数

参数

参数类型

描述

code

String

错误码

message

String

错误描述

状态码: 401

表6 响应Body参数

参数

参数类型

描述

code

String

错误码

message

String

错误描述

状态码: 500

表7 响应Body参数

参数

参数类型

描述

code

String

错误码

message

String

错误描述

请求示例

查询基线检查结果的列表请求样例,查询2024年6月20号到2024年6月27号,遵从包ID为6add7d71-2261-4195-bab7-8ada0f0ed4d2,目录ID为0b78937f-4d9b-4223-9a46-2361e5090be0, 资源类型为iam_user, 按照最近更新时间降序排序,返回第一页,每页10条数据

{
  "limit" : 10,
  "offset" : 0,
  "sort_by" : "last_observed_time",
  "order" : "DESC",
  "from_date" : "2024-06-20T00:00:00.000Z",
  "to_date" : "2024-06-27T23:59:59.999Z",
  "condition" : {
    "conditions" : [ {
      "name" : "compliance_package_id",
      "data" : [ "compliance_package_id", "=", "6add7d71-2261-4195-bab7-8ada0f0ed4d2" ]
    }, {
      "name" : "catalog_id",
      "data" : [ "catalog_id", "=", "0b78937f-4d9b-4223-9a46-2361e5090be0" ]
    }, {
      "name" : "resource.type",
      "data" : [ "resource.type", "=", "iam_user" ]
    } ],
    "logics" : [ "compliance_package_id", "AND", "catalog_id", "AND", "resource.type" ]
  }
}

响应示例

状态码: 200

请求成功

{
  "code" : "00000000",
  "data" : [ {
    "create_time" : "2024-01-03T01:16:21.666+08:00",
    "data_object" : {
      "arrive_time" : "2024-01-03T11:28:03.993Z+0800",
      "baseline_type" : {
        "baseline_type" : "合规检查",
        "baseline_type_en" : "Compliance Check",
        "baseline_type_zh" : "合规检查",
        "category" : "",
        "category_en" : "",
        "category_zh" : "",
        "id" : "23f48a58cXXX162846076cd0"
      },
      "catalog_id" : "9378d1e8-XXX-4aae-XXX-c41cf6829ede",
      "checkitem_id" : "13fcc967-cb49-XXX-811a-9f72ce6ce8ac",
      "compliance_package_id" : "39488f96-XXX-4cc6-XXX-ad3c29b3a6c2",
      "create_time" : "2024-01-02T17:16:21.666Z+0800",
      "data_source" : {
        "company_name" : "xxx",
        "domain_id" : "ac7438b990efXXXb45e8bf4",
        "product_feature" : "SA",
        "product_module" : "Base-line",
        "product_name" : "SecMaster",
        "project_id" : "15645222e8XXX93dab6341da6",
        "region_id" : "cn-north-7",
        "source_type" : 1
      },
      "dataclass_id" : "f846c8e0-XXX-XXX-bcbf-f77190847f08",
      "domain_id" : "ac7438b990eXXX1004eb45e8bf4",
      "domain_name" : "ac7438b99XXX1004eb45e8bf4",
      "end_time" : "2024-01-03T11:28:51.564Z+0800",
      "execitem_id" : "ca2a1361-5738-479c-8c40-d078e775a23a",
      "execitem_version" : 1,
      "first_observed_time" : "2024-01-03T11:28:50.955Z+0800",
      "handle_status" : "qualified",
      "id" : "39c56d70a9c2492XXXd91934cb5cb_13fcc967-XXX-494b-XXX-9f72ce6ce8ac",
      "is_deleted" : false,
      "last_observed_time" : "2024-01-03T11:28:51.564Z+0800",
      "method" : 1,
      "origin_id" : "",
      "project_id" : "15645222e874XXX93dab6341da6",
      "region_id" : "cn-north-7",
      "region_name" : "cn-north-7",
      "resource" : {
        "domain_id" : "ac7438b990eXXX04eb45e8bf4",
        "id" : "39c56d70a9cXXX1934cb5cb",
        "name" : "adfasd",
        "project_id" : "15645222XXXc93dab6341da6",
        "provider" : "xxx",
        "region_id" : "cn-north-7",
        "type" : "agency"
      },
      "severity" : "informational",
      "start_time" : "2024-01-03T11:28:50.955Z+0800",
      "task_id" : "10da8403-XXX-442d-XXX-fa2fdf42a3a1",
      "title" : "项目服务中的委托权限配置检查",
      "trigger_flag" : false,
      "update_time" : "2024-01-03T11:28:51.887Z+0800",
      "workspace_id" : "1350a050-XXX-45e2-XXX-9cbfef116de7"
    },
    "dataclass_ref" : {
      "id" : "f846c8e0-XXX-3767-XXX-f77190847f08"
    },
    "format_version" : 0,
    "id" : "39c56d7XXX278fXXX934cb5cb_13fcc967-cb49-XXX-811a-9f72ce6ce8ac",
    "update_time" : "2024-01-03T19:28:51.887+08:00",
    "version" : 0
  }, {
    "create_time" : "2024-01-03T01:16:21.821+08:00",
    "data_object" : {
      "arrive_time" : "2024-01-03T11:28:03.993Z+0800",
      "baseline_type" : {
        "baseline_type" : "合规检查",
        "baseline_type_en" : "Compliance Check",
        "baseline_type_zh" : "合规检查",
        "category" : "",
        "category_en" : "",
        "category_zh" : "",
        "id" : "23f48a58c5b2fXXX162846076cd0"
      },
      "catalog_id" : "9378d1e8-XXX-4aae-XXX-c41cf6829ede",
      "checkitem_id" : "13fcc967-cb49-XXX-811a-9f72ce6ce8ac",
      "compliance_package_id" : "39488f96-XXX-4cc6-XXX-ad3c29b3a6c2",
      "create_time" : "2024-01-02T17:16:21.821Z+0800",
      "data_source" : {
        "company_name" : "xxx",
        "domain_id" : "ac7438b990efXXX004eb45e8bf4",
        "product_feature" : "SA",
        "product_module" : "Base-line",
        "product_name" : "SecMaster",
        "project_id" : "15645222XXX5c93dab6341da6",
        "region_id" : "cn-north-7",
        "source_type" : 1
      },
      "dataclass_id" : "f846c8e0-XXX-3767-bcbf-f77190847f08",
      "domain_id" : "ac7438b990eXXXb741004eb45e8bf4",
      "domain_name" : "ac7438bXXX37b741004eb45e8bf4",
      "end_time" : "2024-01-03T11:28:51.701Z+0800",
      "execitem_id" : "ca2a1361-XXX-479c-XXX-d078e775a23a",
      "execitem_version" : 1,
      "first_observed_time" : "2024-01-03T11:28:51.565Z+0800",
      "handle_status" : "qualified",
      "id" : "f295575ab57XXX977d9be93ca9fe_13fcc967-XXX-494b-XXX-9f72ce6ce8ac",
      "is_deleted" : false,
      "last_observed_time" : "2024-01-03T11:28:51.701Z+0800",
      "method" : 1,
      "origin_id" : "",
      "project_id" : "15645222e8XXXa985c93dab6341da6",
      "region_id" : "cn-north-7",
      "region_name" : "cn-north-7",
      "resource" : {
        "domain_id" : "ac7438b99XXX1004eb45e8bf4",
        "id" : "f295575ab57bXXXd9be93ca9fe",
        "name" : "apigw_admin_trust_secmaster",
        "project_id" : "15645222e8XXX93dab6341da6",
        "provider" : "xxx",
        "region_id" : "cn-north-7",
        "type" : "agency"
      },
      "severity" : "informational",
      "start_time" : "2024-01-03T11:28:51.565Z+0800",
      "task_id" : "10da8403-4955XXXd-a974-faXXX2a3a1",
      "title" : "项目服务中的委托权限配置检查",
      "trigger_flag" : false,
      "update_time" : "2024-01-03T11:28:52.023Z+0800",
      "workspace_id" : "1350a050-d09a-4XXX-9503-9cbfef116de7"
    },
    "dataclass_ref" : {
      "id" : "f846c8e0-cf0e-XXX-bcbf-XXX7f08"
    },
    "format_version" : 0,
    "id" : "f295575ab57b49XXXe93ca9fe_13fcc967-XXX-494b-XXX-9f72ce6ce8ac",
    "update_time" : "2024-01-03T19:28:52.023+08:00",
    "version" : 0
  } ],
  "page" : 0,
  "size" : 10,
  "success" : true,
  "total" : 2
}

状态码: 400

请求失败

{
  "error_code" : "SecMaster.00040006",
  "error_msg" : "Invalid request parameters"
}

状态码: 401

权限不足

{
  "error_code" : "SecMaster.90010015",
  "error_msg" : "Unauthorized request"
}

状态码: 500

请求失败

{
  "error_code" : "SecMaster.00040011",
  "error_msg" : "Internal system error."
}

SDK代码示例

SDK代码示例如下。

Java

查询基线检查结果的列表请求样例,查询2024年6月20号到2024年6月27号,遵从包ID为6add7d71-2261-4195-bab7-8ada0f0ed4d2,目录ID为0b78937f-4d9b-4223-9a46-2361e5090be0, 资源类型为iam_user, 按照最近更新时间降序排序,返回第一页,每页10条数据

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
package com.huaweicloud.sdk.test;

import com.huaweicloud.sdk.core.auth.ICredential;
import com.huaweicloud.sdk.core.auth.BasicCredentials;
import com.huaweicloud.sdk.core.exception.ConnectionException;
import com.huaweicloud.sdk.core.exception.RequestTimeoutException;
import com.huaweicloud.sdk.core.exception.ServiceResponseException;
import com.huaweicloud.sdk.secmaster.v2.region.SecMasterRegion;
import com.huaweicloud.sdk.secmaster.v2.*;
import com.huaweicloud.sdk.secmaster.v2.model.*;


public class SearchBaselineSolution {

    public static void main(String[] args) {
        // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
        // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
        String ak = System.getenv("CLOUD_SDK_AK");
        String sk = System.getenv("CLOUD_SDK_SK");
        String projectId = "{project_id}";

        ICredential auth = new BasicCredentials()
                .withProjectId(projectId)
                .withAk(ak)
                .withSk(sk);

        SecMasterClient client = SecMasterClient.newBuilder()
                .withCredential(auth)
                .withRegion(SecMasterRegion.valueOf("<YOUR REGION>"))
                .build();
        SearchBaselineRequest request = new SearchBaselineRequest();
        request.withWorkspaceId("{workspace_id}");
        BaselineSearchRequestBody body = new BaselineSearchRequestBody();
        body.withCondition("{\"logics\":[\"compliance_package_id\",\"AND\",\"catalog_id\",\"AND\",\"resource.type\"],\"conditions\":[{\"data\":[\"compliance_package_id\",\"=\",\"6add7d71-2261-4195-bab7-8ada0f0ed4d2\"],\"name\":\"compliance_package_id\"},{\"data\":[\"catalog_id\",\"=\",\"0b78937f-4d9b-4223-9a46-2361e5090be0\"],\"name\":\"catalog_id\"},{\"data\":[\"resource.type\",\"=\",\"iam_user\"],\"name\":\"resource.type\"}]}");
        body.withToDate("2024-06-27T23:59:59.999Z");
        body.withFromDate("2024-06-20T00:00:00.000Z");
        body.withOrder("DESC");
        body.withSortBy("last_observed_time");
        body.withOffset(0);
        body.withLimit(10);
        request.withBody(body);
        try {
            SearchBaselineResponse response = client.searchBaseline(request);
            System.out.println(response.toString());
        } catch (ConnectionException e) {
            e.printStackTrace();
        } catch (RequestTimeoutException e) {
            e.printStackTrace();
        } catch (ServiceResponseException e) {
            e.printStackTrace();
            System.out.println(e.getHttpStatusCode());
            System.out.println(e.getRequestId());
            System.out.println(e.getErrorCode());
            System.out.println(e.getErrorMsg());
        }
    }
}

Python

查询基线检查结果的列表请求样例,查询2024年6月20号到2024年6月27号,遵从包ID为6add7d71-2261-4195-bab7-8ada0f0ed4d2,目录ID为0b78937f-4d9b-4223-9a46-2361e5090be0, 资源类型为iam_user, 按照最近更新时间降序排序,返回第一页,每页10条数据

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
# coding: utf-8

import os
from huaweicloudsdkcore.auth.credentials import BasicCredentials
from huaweicloudsdksecmaster.v2.region.secmaster_region import SecMasterRegion
from huaweicloudsdkcore.exceptions import exceptions
from huaweicloudsdksecmaster.v2 import *

if __name__ == "__main__":
    # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak = os.environ["CLOUD_SDK_AK"]
    sk = os.environ["CLOUD_SDK_SK"]
    projectId = "{project_id}"

    credentials = BasicCredentials(ak, sk, projectId)

    client = SecMasterClient.new_builder() \
        .with_credentials(credentials) \
        .with_region(SecMasterRegion.value_of("<YOUR REGION>")) \
        .build()

    try:
        request = SearchBaselineRequest()
        request.workspace_id = "{workspace_id}"
        request.body = BaselineSearchRequestBody(
            condition="{\"logics\":[\"compliance_package_id\",\"AND\",\"catalog_id\",\"AND\",\"resource.type\"],\"conditions\":[{\"data\":[\"compliance_package_id\",\"=\",\"6add7d71-2261-4195-bab7-8ada0f0ed4d2\"],\"name\":\"compliance_package_id\"},{\"data\":[\"catalog_id\",\"=\",\"0b78937f-4d9b-4223-9a46-2361e5090be0\"],\"name\":\"catalog_id\"},{\"data\":[\"resource.type\",\"=\",\"iam_user\"],\"name\":\"resource.type\"}]}",
            to_date="2024-06-27T23:59:59.999Z",
            from_date="2024-06-20T00:00:00.000Z",
            order="DESC",
            sort_by="last_observed_time",
            offset=0,
            limit=10
        )
        response = client.search_baseline(request)
        print(response)
    except exceptions.ClientRequestException as e:
        print(e.status_code)
        print(e.request_id)
        print(e.error_code)
        print(e.error_msg)

Go

查询基线检查结果的列表请求样例,查询2024年6月20号到2024年6月27号,遵从包ID为6add7d71-2261-4195-bab7-8ada0f0ed4d2,目录ID为0b78937f-4d9b-4223-9a46-2361e5090be0, 资源类型为iam_user, 按照最近更新时间降序排序,返回第一页,每页10条数据

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
package main

import (
	"fmt"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic"
    secmaster "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/secmaster/v2"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/services/secmaster/v2/model"
    region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/secmaster/v2/region"
)

func main() {
    // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak := os.Getenv("CLOUD_SDK_AK")
    sk := os.Getenv("CLOUD_SDK_SK")
    projectId := "{project_id}"

    auth := basic.NewCredentialsBuilder().
        WithAk(ak).
        WithSk(sk).
        WithProjectId(projectId).
        Build()

    client := secmaster.NewSecMasterClient(
        secmaster.SecMasterClientBuilder().
            WithRegion(region.ValueOf("<YOUR REGION>")).
            WithCredential(auth).
            Build())

    request := &model.SearchBaselineRequest{}
	request.WorkspaceId = "{workspace_id}"
	var conditionBaselineSearchRequestBody interface{} = "{\"logics\":[\"compliance_package_id\",\"AND\",\"catalog_id\",\"AND\",\"resource.type\"],\"conditions\":[{\"data\":[\"compliance_package_id\",\"=\",\"6add7d71-2261-4195-bab7-8ada0f0ed4d2\"],\"name\":\"compliance_package_id\"},{\"data\":[\"catalog_id\",\"=\",\"0b78937f-4d9b-4223-9a46-2361e5090be0\"],\"name\":\"catalog_id\"},{\"data\":[\"resource.type\",\"=\",\"iam_user\"],\"name\":\"resource.type\"}]}"
	toDateBaselineSearchRequestBody:= "2024-06-27T23:59:59.999Z"
	fromDateBaselineSearchRequestBody:= "2024-06-20T00:00:00.000Z"
	orderBaselineSearchRequestBody:= "DESC"
	sortByBaselineSearchRequestBody:= "last_observed_time"
	offsetBaselineSearchRequestBody:= int32(0)
	limitBaselineSearchRequestBody:= int32(10)
	request.Body = &model.BaselineSearchRequestBody{
		Condition: &conditionBaselineSearchRequestBody,
		ToDate: &toDateBaselineSearchRequestBody,
		FromDate: &fromDateBaselineSearchRequestBody,
		Order: &orderBaselineSearchRequestBody,
		SortBy: &sortByBaselineSearchRequestBody,
		Offset: &offsetBaselineSearchRequestBody,
		Limit: &limitBaselineSearchRequestBody,
	}
	response, err := client.SearchBaseline(request)
	if err == nil {
        fmt.Printf("%+v\n", response)
    } else {
        fmt.Println(err)
    }
}

更多

更多编程语言的SDK代码示例,请参见API Explorer的代码示例页签,可生成自动对应的SDK代码示例。

状态码

状态码

描述

200

请求成功

400

请求失败

401

权限不足

500

请求失败

错误码

请参见错误码