The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add a New Attack Filter

Prev Next

This URL adds a new attack filter.

Resource URL

POST /attackfilter

Request Parameters

Field Name

Description

Data Type

Mandatory

name

Attack filter name

String

Yes

attackFilterId

Attack filter id, not required for POST

Number

No

Description

Description

String

No

DomainId

Id of domain to which this attack filter belongs to

Number

Yes

LastModTs

Last modified timestamp

String

No

Type

Attack filter type, can be "IPV_4" / "IPV_6" / "TCP_UDP_PORT" / "IPV_4_TCP_UDP_PORT" / "IPV_6_TCP_UDP_PORT"

String

Yes

MatchCriteria

Attack filter exclusion

Object

Yes

Details of MatchCriteria:

Field Name

Description

Data Type

Mandatory

Exclusion

List of IP - port exclusions

Array

Yes

Details of object in Exclusion (depends on the Type defined):

Field Name

Description

Data Type

Mandatory

Ip

IPv4 or IPv6 IP

Object

No

Port

TCP / UDP port

Object

No

Details of Ip:

Field Name

Description

Data Type

Mandatory

srcStart

Source start IP

String

No

srcEnd

Source end IP

String

No

destStart

Destination start IP

String

No

destEnd

Destination end IP

String

No

srcMode

Source IP mode, can be "ANY_IP" / "ANY_EXTERNAL_IP" / "ANY_INTERNAL_IP" / "RANGE_IP" / "SINGLE_IP"

String

Yes

destMode

Destination IP mode, can be "ANY_IP" / "ANY_EXTERNAL_IP" / "ANY_INTERNAL_IP" / "RANGE_IP" / "SINGLE_IP"

String

Yes

Details of Port:

Field Name

Description

Data Type

Mandatory

srcPort

Source port

String

No

destPort

Destination port

String

No

srcPortMode

Source port mode, can be "ANY_PORT" / "TCP_OR_UDP" / "TCP" / "UDP"

String

Yes

destPortMode

Destination port mode, can be "ANY_PORT" / "TCP_OR_UDP" / "TCP" / "UDP"

String

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

createdResourceId

Unique ID of the created attack filter

Number

Example

Request

POST https://<NSM_IP>/sdkapi/attackfilter

Payload:
 {
		"DomainId": 0,
		"Description": "try ",
 		"MatchCriteria": {
			"Exclusion": [
 	{
			"Ip": {
 				"destEnd": "1.1.1.18",
				"destMode": "RANGE_IP",
 				"srcMode": "SINGLE_IP",
 				"srcStart": "1.1.1.1",
 				"destStart": "1.1.1.13",
 				"srcEnd": "1.1.1.11"
		},
		"Port": {
 				"srcPortMode": "TCP",
				"srcPort": "85",
				 "destPort": "89",
				 "destPortMode": "TCP"
			 }
		 }
 	]
 },
	"Type": "IPV_4_AND_TCP_UDP_PORT",
	"name": "test1"
}

Response

{
 "createdResourceId":419
 }

Error Information

Following error codes are returned by this URL:

S.No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

400

1001

Internal error

2

404

1105

Invalid domain

3

400

1409

Attack filter name should not be greater than 40 chars

4

400

1118

Please provide a name

5

400

1401

Unable to set attack filter type

6

400

1404

Please provide IP

7

400

1406

Invalid IP Format

8

400

1407

Please provide Port

9

400

1414

Invalid source and destination combination

10

400

1415

Port not valid, please enter a number between 1 and 65535

11

400

1416

IP mode not valid

12

400

1418

Start IP should be less than end IP