The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Replace YARA rule file request

Prev Next

This API is used to update or replace the YARA rule file in the existing ruleset.

PUT https://<etp_instance_addr>/api/v1/policies/policy_uuid/configuration/rules/yara/rulesets/ruleset_uuid/file

Required header:

x-fireeye-api-key: <key>—Specifies your personal API key.

Content-Type: multipart/form-data—Content-type of the request body.

Options

  • policy_uuid—Universally unique identifier (UUID) of the policy.

  • ruleset_uuid—UUID of the ruleset.

Request body

It must be a YARA file as a new_file.yara attachment.

Example of the request

Values for ID and other fields are for illustration only.

PUT https://etp.us.fireeye.com/api/v1/policies/6d92fac1-f8e6-11eb-993c-02a7fc9eb3d9/configuration/rules/yara/rulesets/2aed1c8a-96c2-464a-46c7-1cfb135642a9/file

Example of the response

{
    "data": {
        "policy_master_uuid": "uuid1",
        "uuid": "ruleset1_uuid",
        "name": "ruleset1",
        "description": "desc1",
        "override_rule_weights": true,
        "default_file_weight": 49,
        "content_type": "base",
        "attachment_type": "common",
        "yara_file_name": "new_file.yara",
        "enabled": true
    },
    "meta": {
        "total": 1,
        "copyright": "Copyright 2021 FireEye Inc",
        "type": "Yara Rules"
    }
}

cURL code sample: replace YARA rule file

curl -k -XPUT https://etp.us.fireeye.com/api/v1/policies/6d92fac1-f8e6-11eb-993c-02a7fc9eb3d9/configuration/rules/yara/rulesets/2aed1c8a-96c2-464a-46c7-1cfb135642a9/file -H 'Content-Type:multipart/form-data' -H 'x-fireeye-api-key: <feye-key>' -F file=@/Users/mukthi.alva/Downloads/2.yara

This cURL sample includes the following options:

  • -X PUT—This option changes the HTTP method to PUT.

  • --header "Content-Type: multipart/form-data"—This header specifies that the server's response body is expected to be in multipart/form-data format.

  • --header 'x-fireeye-api-key: <feye-key>'—This header specifies your personal API key.

  • https://etp.us.fireeye.com/api/v1/policies/6d92fac1-f8e6-11eb-993c-02a7fc9eb3d9/configuration/rules/yara/rulesets/2aed1c8a-96c2-464a-46c7-1cfb135642a9/file—The replace YARA rule file URL. Replace etp.us.fireeye.com with the IP address of your Email Security — Cloud instance and 6d92fac1-f8e6-11eb-993c-02a7fc9eb3d9 with the UUID of the YARA policy.

Results

This example returns the ruleset with the replaced YARA rule file.