The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add Alert Exception

Prev Next

This URL adds a new alert exception.

Resource URL

POST /alertexception

Request Parameters

Payload Request Parameters:

Field Name

Description

Data Type

Mandatory

attackId

Unique hexadecimal attack id

String

yes

sourceIp

IPv4/IPv6 address/"ANY"

String

Yes

destinationIp

IPv4/IPv6 address/"ANY"

String

Yes

expiration

Expiration can be "ONE_DAY" / "TWO_DAYS" / "THREE_DAYS" / "ONE_WEEK" / "ONE_MONTH"/" ONE_YEAR"

String

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

createdResourceId

Unique id of the created alert exception

Number

Example

Request

POST https://<NSM_IP>/sdkapi/alertexception

{
	"attackId" : "0x42C03A00",
	"sourceIp" : "2.2.2.2",
	"destinationIp" : "Any",
	"expiration" : "ONE_DAY"
}

Response

{
"createdResourceId":120
}

Error Information

Following error codes are returned by this URL:

S.No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

500

1001

Internal error

2

404

1105

Invalid domain

3

400

1402

Invalid attack id

4

400

1406

Invalid IP format

5

400

4001

Source and destination can contain either IPV4/IPV6, but not both simultaneously

6

400

4003

Similar alert exception already exist

7

400

4004

Source and destination IP cannot be same

8

400

4005

Alert exception limit exceeded

9

400

4006

Attack id, source and destination IP, all the three can't be any