public static final class DescribeSuspEventsResponseBody.SuspEvents.Builder extends Object
public DescribeSuspEventsResponseBody.SuspEvents.Builder advanced(Boolean advanced)
Indicates whether the alert event was analyzed offline.
example:true
public DescribeSuspEventsResponseBody.SuspEvents.Builder alarmEventName(String alarmEventName)
The name of the alert event.
example:login_common_location
public DescribeSuspEventsResponseBody.SuspEvents.Builder alarmEventNameDisplay(String alarmEventNameDisplay)
The name of the alert.
example:Login with unusual location
public DescribeSuspEventsResponseBody.SuspEvents.Builder alarmEventType(String alarmEventType)
The type of the alert event.
example:Unusual Logon
public DescribeSuspEventsResponseBody.SuspEvents.Builder alarmEventTypeDisplay(String alarmEventTypeDisplay)
The display name of the type of the alert event.
example:Unusual Logon
public DescribeSuspEventsResponseBody.SuspEvents.Builder alarmUniqueInfo(String alarmUniqueInfo)
The unique ID of the alert event.
example:8df914418f****
public DescribeSuspEventsResponseBody.SuspEvents.Builder appName(String appName)
The name of the application to which the alert event belongs.
example:pro-deploy-tibasic
public DescribeSuspEventsResponseBody.SuspEvents.Builder autoBreaking(Boolean autoBreaking)
Indicates whether automatic defense is enabled.
example:true
public DescribeSuspEventsResponseBody.SuspEvents.Builder canBeDealOnLine(Boolean canBeDealOnLine)
Indicates whether you can handle the alert event online, such as quarantining the source file of the malicious process. Valid values:
true
public DescribeSuspEventsResponseBody.SuspEvents.Builder canCancelFault(Boolean canCancelFault)
Indicates whether you can cancel marking the alert event as a false positive. Valid values:
false
public DescribeSuspEventsResponseBody.SuspEvents.Builder containHwMode(Boolean containHwMode)
Indicates whether the safeguard mode for major activities is enabled for the server. Valid values:
false
public DescribeSuspEventsResponseBody.SuspEvents.Builder containerId(String containerId)
The ID of the container.
example:container_1648601865161_14925_02_000****
public DescribeSuspEventsResponseBody.SuspEvents.Builder containerImageId(String containerImageId)
The ID of the container image.
example:sha256:2e5a3b0ae5f452b3cb458789a9a7542ef40035a84318469a8528c5e444db1****
public DescribeSuspEventsResponseBody.SuspEvents.Builder containerImageName(String containerImageName)
The name of the container image.
example:centos7_apache:v1.0.1
public DescribeSuspEventsResponseBody.SuspEvents.Builder dataSource(String dataSource)
The source of data. This parameter can be ignored.
example:aegis_suspicious_****
public DescribeSuspEventsResponseBody.SuspEvents.Builder desc(String desc)
The impact of the alert event.
example:webshell
public DescribeSuspEventsResponseBody.SuspEvents.Builder details(List<DescribeSuspEventsResponseBody.Details> details)
The details of the alert event.
public DescribeSuspEventsResponseBody.SuspEvents.Builder detectSource(String detectSource)
public DescribeSuspEventsResponseBody.SuspEvents.Builder displaySandboxResult(Boolean displaySandboxResult)
Indicates whether the alert event can be detected by cloud sandbox. Valid values:
true
public DescribeSuspEventsResponseBody.SuspEvents.Builder eventNotes(List<DescribeSuspEventsResponseBody.EventNotes> eventNotes)
The note information about the alert event.
public DescribeSuspEventsResponseBody.SuspEvents.Builder eventStatus(Integer eventStatus)
The status of the alert event. Valid values:
1
public DescribeSuspEventsResponseBody.SuspEvents.Builder eventSubType(String eventSubType)
The subtype of the alert event.
example:login_common_location
public DescribeSuspEventsResponseBody.SuspEvents.Builder hasTraceInfo(Boolean hasTraceInfo)
Indicates whether the alert event has tracing information. Valid values:
true
public DescribeSuspEventsResponseBody.SuspEvents.Builder id(Long id)
The unique ID of the alert event.
example:1000
public DescribeSuspEventsResponseBody.SuspEvents.Builder imageUuid(String imageUuid)
The UUID of the image.
example:70489fb520cea585ad9761d5a842****
public DescribeSuspEventsResponseBody.SuspEvents.Builder instanceId(String instanceId)
The instance ID of the affected asset.
example:i-9dp6dwsxdl9z5u1e2f****
public DescribeSuspEventsResponseBody.SuspEvents.Builder instanceName(String instanceName)
The name of the associated instance.
example:nginx
public DescribeSuspEventsResponseBody.SuspEvents.Builder internetIp(String internetIp)
The public IP address of the associated instance.
example:1.2.XX.XX
public DescribeSuspEventsResponseBody.SuspEvents.Builder intranetIp(String intranetIp)
The private IP address of the associated instance.
example:100.100.XX.XX
public DescribeSuspEventsResponseBody.SuspEvents.Builder k8sClusterId(String k8sClusterId)
The ID of the Kubernetes cluster.
example:c517b37e1401e4961b3951863a49a****
public DescribeSuspEventsResponseBody.SuspEvents.Builder k8sClusterName(String k8sClusterName)
The name of the Kubernetes cluster.
example:k8s-daily
public DescribeSuspEventsResponseBody.SuspEvents.Builder k8sNamespace(String k8sNamespace)
The namespace of the Kubernetes cluster.
example:default
public DescribeSuspEventsResponseBody.SuspEvents.Builder k8sNodeId(String k8sNodeId)
The ID of the Kubernetes node.
example:i-bp14a1ay8e0aa9t0****
public DescribeSuspEventsResponseBody.SuspEvents.Builder k8sNodeName(String k8sNodeName)
The name of the Kubernetes node.
example:N/A
public DescribeSuspEventsResponseBody.SuspEvents.Builder k8sPodName(String k8sPodName)
The name of the Kubernetes pod.
example:myapp-pod
public DescribeSuspEventsResponseBody.SuspEvents.Builder largeModel(Boolean largeModel)
Indicates whether the large model analysis tag is supported. Valid values:
true
public DescribeSuspEventsResponseBody.SuspEvents.Builder lastTime(String lastTime)
The time when the alert event was last detected.
example:2018-09-26 01:51:01
public DescribeSuspEventsResponseBody.SuspEvents.Builder lastTimeStamp(Long lastTimeStamp)
The timestamp when the alert event was last detected. Unit: milliseconds.
example:1631699497000
public DescribeSuspEventsResponseBody.SuspEvents.Builder level(String level)
The severity of the alert event. Valid values:
serious
public DescribeSuspEventsResponseBody.SuspEvents.Builder maliciousRuleStatus(String maliciousRuleStatus)
The status of the malicious behavior defense rule. Valid values:
open
public DescribeSuspEventsResponseBody.SuspEvents.Builder markList(List<String> markList)
The tags of the alert events.
public DescribeSuspEventsResponseBody.SuspEvents.Builder markMisRules(String markMisRules)
The advanced whitelist rule.
example:[{"uuid":"ALL","field":"gmtModified","operate":"contains","fieldValue":"222"}]
public DescribeSuspEventsResponseBody.SuspEvents.Builder name(String name)
The complete name of the alert event.
example:Unusual Logon-Login with unusual location
public DescribeSuspEventsResponseBody.SuspEvents.Builder occurrenceTime(String occurrenceTime)
The time when the alert event was first detected.
example:2018-09-26 01:51:01
public DescribeSuspEventsResponseBody.SuspEvents.Builder occurrenceTimeStamp(Long occurrenceTimeStamp)
The timestamp when the alert event was first detected. Unit: milliseconds.
example:1631699497000
public DescribeSuspEventsResponseBody.SuspEvents.Builder operateErrorCode(String operateErrorCode)
The handling result code of the alert event.
example:kill_and_quara.Success
public DescribeSuspEventsResponseBody.SuspEvents.Builder operateMsg(String operateMsg)
The handing result message of the alert event.
example:success
public DescribeSuspEventsResponseBody.SuspEvents.Builder operateTime(Long operateTime)
The handling timestamp of the alert event. Unit: milliseconds.
example:1631699497000
public DescribeSuspEventsResponseBody.SuspEvents.Builder saleVersion(String saleVersion)
The edition of Security Center in which the alert event can be detected. Valid values:
1
public DescribeSuspEventsResponseBody.SuspEvents.Builder securityEventIds(String securityEventIds)
The ID of the associated alert event.
example:270789
public DescribeSuspEventsResponseBody.SuspEvents.Builder sourceAliUid(Long sourceAliUid)
The ID of the Alibaba Cloud account within which an alert is generated.
example:196072141348****
public DescribeSuspEventsResponseBody.SuspEvents.Builder stages(String stages)
The stage at which the attack is detected.
example:"["authority_maintenance"]"
public DescribeSuspEventsResponseBody.SuspEvents.Builder supportOperateCode(String supportOperateCode)
Supported alarm operation types:
AI.real_attack
public DescribeSuspEventsResponseBody.SuspEvents.Builder tacticItems(List<DescribeSuspEventsResponseBody.TacticItems> tacticItems)
The display name of the attack stage.
public DescribeSuspEventsResponseBody.SuspEvents.Builder uniqueInfo(String uniqueInfo)
The unique key of the alert.
example:e17e****
public DescribeSuspEventsResponseBody.SuspEvents.Builder uuid(String uuid)
The unique ID of the associated instance.
example:bf6b30d3-eea8-4924-9f0a-****
public DescribeSuspEventsResponseBody.SuspEvents.Builder clusterId(String clusterId)
The ID of the cluster.
example:c2051775877374cccbf68af596e6****
public DescribeSuspEventsResponseBody.SuspEvents build()
Copyright © 2026. All rights reserved.