The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Client group

Prev Next

The following are client group APIs that are used from shell on the appliance:

GET http://localhost:8085/config/v1/clientgroup
POST http://localhost:8085/config/v1/clientgroup
PUT http://localhost:8085/config/v1/clientgroup/{group-name} 
DELETE http://localhost:8085/config/v1/clientprofile/{group-name} 

The following are client group APIs that are used from remote host:

GET https://IA_IP_Address/config/v1/clientgroup
POST https://IA_IP_Address/config/v1/clientgroup
PUT https://IA_IP_Address/config/v1/clientgroup/(group-name)
DELETE  https://IA_IP_Address/config/v1/clientgroup/(group-name)

Samples

curl -k -u npadmin:Fireeye@123 -XGET https://IA_IP_Address/config/v1/clientgroup
curl -k -u npadmin:Fireeye@123 https://IA_IP_Address/config/v1/clientgroup -XPOST --data @group.json
curl -k -u npadmin:Fireeye@123 https://IA_IP_Address/config/v1/clientgroup/group_test -XDELETE

Example JSON

{

        "name": "group_test",
        "flow_whitelist": [
            {
                "srcIp": "1.1.1.1",
                "destIp": "2.2.2.2",
                "srcPort": 10,
                "destPort": 20,
                "protocol": "TCP"
            }
        ],
        "poll_interval": 30,
        "detection_engines": [
            "dga",
            "beaconing",
            "data-exfill"
        ],
        "profile": "name_of_client_profile",
        "home_network": [
            "1.1.1.1/16"
        ],
        "px_host": ["PX_IP_Address"]
    }

Where:

  • Name—Name of the client group to be created.

  • Client ID— ID of client profile. GET client profile API provides the output containing its client-id.

  • Token—Token generated after client group is created. This field must be left blank in JSON.

  • Profile—Name of the client profile being associated with client group.

  • Hash—Hash value of the client profile being associated with client group. GET client profile API provides the output containing its hash.

  • Px_host— IP of PX to be added to client group.

Sample Response of POST

{
    "client_id": "32d642ece9fd0dcb",
    "token": "32d642ece9fd0dcb109dd9fdc000e783"
}

Where:

  • Client ID— ID of client profile. GET client profile API provides the output containing its client-id.

  • Token—Token generated after client group is created. This token is used to associate sensors, such as Network Security or IPS with Network Detection and Response)