The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add a Packet Capture Rule Template

Prev Next

This URL adds a packet capture rule template.

Resource URL

POST /sensor/<sensor_id>/packetcaptureruletemplate

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

sensor_id

Sensor id. Give -1 if all the quarantine hosts are needed

number

Yes

Payload Request Parameters:

Field Name

Description

Data Type

Mandatory

templateName

Name of template

String

Yes

visibleToCild

Visible to child or not

Boolean

Yes

rule

List of rules

Array

Yes

Details of object in rule:

Field Name

Description

Data Type

Mandatory

traffic

Traffic

String

Yes

protocol

Protocol

String

Yes

ipVersion

IP version

String

Yes

fragmentsOnly

Fragments only

Boolean

Yes

sourceIP

Source IP

String

No

sourceMask

Source mask

Number

No

sourcePort

Source port

Number

No

destinationIP

Destination IP

String

No

destinationMask

Destination mask

Number

No

destinationPort

Destination port

Number

No

vlanId

VLAN id

Number

No

protocolNumber

Protocol number

Number

No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

createdResourceId

Unique id of the created device

Number

Example

Request

POST https://<NSM_IP>/sdkapi/sensor/1001/packetcaptureruletemplate

Payload

{
	"templateName": "test",
	"visibleToCild": true,
	"rule": [{
"traffic": "ALL",
		"protocol": "TCP",
		"ipVersion": "IPV_4",
		"fragmentsOnly": false,
		"sourceIP": "0.0.0.0",
		"sourceMask": 0,
		"sourcePort": 0,
		"destinationIP": "0.0.0.0",
		"destinationMask": 0,
		"destinationPort": 0,
		"vlanId": 0,
		"protocolNumber": 0
	}]
}

Response

{
"createdResourceId":101
}

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1106

Invalid Sensor

2

500

1124

The Sensor is inactive

3

400

6201

Packet capture not supported on this Sensor

4

400

6202

Packet capture duration should be between 1 and 9999

5

400

6203

Packet capture size should be between 1 and <maxSize>

6

400

6204

SCP server IP, username, password, and capture size are mandatory

7

400

6205

SCP server username should not contain space and special characters other than {-,_,.}

8

400

6210

Protocol number should be between 1 and 65535 when PROTOCOL_NUMBER is selected as protocol while you have given --> <protocol_number>