The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add a New Attack Filter

Prev Next

This URL adds a new attack filter.

Resource URL

POST /attackfilter

Request Parameters

Field Name Description Data Type Mandatory
name Attack filter name String Yes
attackFilterId Attack filter id, not required for POST Number No
Description Description String No
DomainId Id of domain to which this attack filter belongs to Number Yes
LastModTs Last modified timestamp String No
Type Attack filter type, can be "IPV_4" / "IPV_6" / "TCP_UDP_PORT" / "IPV_4_TCP_UDP_PORT" / "IPV_6_TCP_UDP_PORT" String Yes
MatchCriteria Attack filter exclusion Object Yes

Details of MatchCriteria:

Field Name Description Data Type Mandatory
Exclusion List of IP - port exclusions Array Yes

Details of object in Exclusion (depends on the Type defined):

Field Name Description Data Type Mandatory
Ip IPv4 or IPv6 IP Object No
Port TCP / UDP port Object No

Details of Ip:

Field Name Description Data Type Mandatory
srcStart Source start IP String No
srcEnd Source end IP String No
destStart Destination start IP String No
destEnd Destination end IP String No
srcMode Source IP mode, can be "ANY_IP" / "ANY_EXTERNAL_IP" / "ANY_INTERNAL_IP" / "RANGE_IP" / "SINGLE_IP" String Yes
destMode Destination IP mode, can be "ANY_IP" / "ANY_EXTERNAL_IP" / "ANY_INTERNAL_IP" / "RANGE_IP" / "SINGLE_IP" String Yes

Details of Port:

Field Name Description Data Type Mandatory
srcPort Source port String No
destPort Destination port String No
srcPortMode Source port mode, can be "ANY_PORT" / "TCP_OR_UDP" / "TCP" / "UDP" String Yes
destPortMode Destination port mode, can be "ANY_PORT" / "TCP_OR_UDP" / "TCP" / "UDP" String Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
createdResourceId Unique ID of the created attack filter Number

Example

Request

POST https://%3CNSM_IP%3E/sdkapi/attackfilter
Payload:
 {
		"DomainId": 0,
		"Description": "try ",
 		"MatchCriteria": {
			"Exclusion": [
 	{
			"Ip": {
 				"destEnd": "1.1.1.18",
				"destMode": "RANGE_IP",
 				"srcMode": "SINGLE_IP",
 				"srcStart": "1.1.1.1",
 				"destStart": "1.1.1.13",
 				"srcEnd": "1.1.1.11"
		},
		"Port": {
 				"srcPortMode": "TCP",
				"srcPort": "85",
				 "destPort": "89",
				 "destPortMode": "TCP"
			 }
		 }
 	]
 },
	"Type": "IPV_4_AND_TCP_UDP_PORT",
	"name": "test1"
} 

Response

{
 "createdResourceId":419
 } 
 

Error Information

Following error codes are returned by this URL:

S.No HTTP Error Code SDK API errorId SDK API errorMessage
1 400 1001 Internal error
2 404 1105 Invalid domain
3 400 1409 Attack filter name should not be greater than 40 chars
4 400 1118 Please provide a name
5 400 1401 Unable to set attack filter type
6 400 1404 Please provide IP
7 400 1406 Invalid IP Format
8 400 1407 Please provide Port
9 400 1414 Invalid source and destination combination
10 400 1415 Port not valid, please enter a number between 1 and 65535
11 400 1416 IP mode not valid
12 400 1418 Start IP should be less than end IP