Skip to Content
WEB应用防火墙 UEWAF获取误报记录列表 - DescribeWafAttackFalseAlarmListInfo

获取误报记录列表 - DescribeWafAttackFalseAlarmListInfo

简介

获取误报记录列表

定义

公共参数

参数名类型描述信息必填
Actionstring对应的 API 指令名称,当前 API 为 DescribeWafAttackFalseAlarmListInfoYes
PublicKeystring用户公钥,可从 控制台 获取Yes
Signaturestring根据公钥及 API 指令生成的用户签名,参见 签名算法Yes

请求参数

参数名类型描述信息必填
ProjectIdstring项目ID。不填写为默认项目,子帐号必须填写。 请参考GetProjectList接口No
Offsetint记录 偏移,等效于PageNumYes
Limitint记录限制数目,等效于PageSizeYes
FullDomainstring要查询的域名,优先级比Domain高No

响应字段

字段名类型描述信息必填
RetCodeint返回状态码,为 0 则为成功返回,非 0 为失败Yes
Actionstring操作指令名称Yes
Messagestring返回错误消息,当 RetCode 非 0 时提供详细的描述信息No
TotalCountint误报记录总数Yes
DetailListarray[WafAttack]误报记录列表,参考WafAttackYes

数据模型

WafAttack

字段名类型描述信息必填
Regionstring区域No
RequestHeadersstring请求头部Yes
RequestBodystring请求bodyYes
ClientPortstring客户端端口Yes
RequestIDstring请求uidYes
ClientIPInfoCityInfo源IP信息Yes
Protocolstring协议No
ServerNamestring服务器名称No
DestIpstring目标IP地址No
Portstring端口No
Alertsarray[WafAlert]告警匹配信息,参考WafAlertNo
Attackstring攻击类型No
Methodstring请求方法No
FalsePositiveboolean是否误报No
RiskRankstring风险等级No
TimeStampint攻击时间戳No
Hoststring主机名No
Refererstring引用地址No
Countint攻击次数No
UristringURINo
Clientstring客户端No
Modestring工作模式No
Actionstring匹配动作No
UAstring用户代理No
Argsstring参数No
IdstringNo

CityInfo

字段名类型描述信息必填
CountryNamestring国家No
RegionNamestring区域No
CityNamestring城市No
OwnerDomainstring所属域名No
Latitudestring纬度No
Longitudestring经度No
Timezonestring时区No

WafAlert

字段名类型描述信息必填
Matchstring命中内容Yes
Descriptionstring规则描述No
Idint匹配规则IDNo

示例

请求示例

https://api.tnqacloud.com/?Action=DescribeWafAttackFalseAlarmListInfo &ProjectId=org-xxx &Domain=www.test.com &Offset=0 &Limit=10 &FullDomain=izRcaHFo

响应示例

{ "Action": "DescribeWafAttackFalseAlarmListInfoResponse", "DetailList": [ { "AccessId": "183.238.16.138-a9736253", "Action": "DENY", "Alerts": [ { "Description": "XSS", "Id": 32003, "Match": { "0": "\u003cscript", "1": "\u003cscript", "2": "\u003c", "5": "script" } } ], "Args": "", "Attack": "xss", "Client": "183.238.16.138", "ClientIPInfo": { "city_name": "深圳", "country_name": "中国", "latitude": "22.547", "longitude": "114.085947", "owner_domain": "", "region_name": "广东", "timezone": "Asia/Shanghai" }, "Count": 1, "DestIp": "106.75.79.224", "FalsePositive": true, "Host": "www.test.com", "Id": "5e8c1dbb243527db1df82677", "Method": "GET", "Mode": "SIMULATE", "Port": "80", "Protocol": "http", "Referer": "NULL", "Region": "cn-bj", "RequestBody": null, "RequestHeaders": { "Accept": "text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8", "AcceptEncoding": "", "AcceptLanguage": "en-US", "CacheControl": "", "Connection": "", "Cookie": "", "Host": "www.test.com", "UpgradeInsecureRequests": "", "UserAgent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; Tablet PC 2.0)", "XForwardFor": "" }, "RiskRank": "high", "ServerName": "www.test.com", "TimeStamp": 1586240955, "TopId": 50146955, "UA": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; Tablet PC 2.0)", "Uri": "/home.html?user=\u0026password=\u0026action!login:cantLogin%3Cscript%3Ealert(1344)%3C/script%3E=AppScan" } ], "RetCode": 0, "TotalCount": 1 }