Tenant Cloud
Security
Cloud Workload Protection Platform
Intrusion Detection - High-Risk Command APIs
EditBashRules
1. Interface Description
Interface request domain name: cwp.api3.convergecloud.com.
API for creating or modifying an anti-high-risk command rule
Default interface request rate limit: 20 times per second.
Interface update time: 2022-05-20 15:12:33.
The interface is both signature verification and authentication.
2. Input Parameters
The following list of request parameters only lists interface request parameters and some public parameters, For a complete list of public parameters see public request parameters.
| Parameter name | Required | Allow NULL | Type | Description |
|---|---|---|---|---|
| Action | Yes | No | String | Public parameter, The value of this interface: EditBashRules |
| Version | Yes | No | String | Public parameter, The value of this interface: 2018-02-28 |
| Region | No | No | String | Public parameter,Regional information This interface does not need to pass this parameter. |
| DealOldEvents | No | No | Uint64 | Whether to add previous events to the allowlist. 0: no. 1: yes. Example: 1 |
| EventId | No | No | Uint64 | ID of the event, which must be passed in when you add the event to the allowlist. Example: 10023 |
| HostIp | No | No | String | Server IP address. Example: 1.1.1.1 |
| Id | No | No | Uint64 | Rule ID. If you want to create a rule, leave this parameter empty. Example: 1 |
| IsGlobal | No | No | Uint64 | Specifies whether it is a global rule. 1: yes. 2: no. Default value: 0. Example: 1 |
| Level | No | No | Uint64 | Risk severity. 0: no risk. 1: high. 2: medium. 3: low. Example: 1 |
| Name | No | No | String | Rule name. If you want to modify a rule, the rule name cannot be changed. Example: Rule name |
| Rule | No | No | String | This API is deprecated. Use the ModifyBashPolicy API instead. Example: sh cmdline |
| Uuids | No | No | Array of String | Agent IDs. Example: ["05f0bcab-726c-4ea4-8109-bcd03d5598f7"] |
| White | No | No | Uint64 | 0: blocklist. 1: allowlist. Example: 1 |
3. Output Parameters
| Parameter name | Type | Description |
|---|---|---|
| RequestId | String | Unique request id, Each request will return. The RequestId of the request needs to be provided when locating the problem. |
4. Error Code
The following lists only the error codes related to the interface business logic, For other error codes, see public ErrorCode.
| Error Code | Description |
|---|---|
| InternalError | Internal error. |
| InvalidParameter.ParsingError | Parameter parsing error. |
| InvalidParameter.MissingParameter | Missing parameter. |
| InvalidParameter.InvalidFormat | Incorrect parameter format. |
| MissingParameter | Missing parameter. |
| ResourceNotFound | The resource does not exist. |
| InvalidParameter.RegexRuleError | The format of the regular expression parameter is invalid. |
| InvalidParameter.RuleHostipErr | Incorrect server IP address for a rule API. |
| InvalidParameter.IpNoValid | Invalid IP address format. |
| InvalidParameter | Invalid parameter. |
| InvalidParameterValue | The parameter value is invalid. |