This URL creates a new ignore rule.
Resource URL
POST /domain/<domainId>/attackfilter82
Request Parameters
URL Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| domain_id | Domain id | Number | Yes |
Payload Request Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| attackFilter | The details of the ignore rules created within the given domain | Object | Yes |
Details of attackFilter:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| id | The unique identifier for an ignore rule | Number | No |
| state | Field to indicate whether an ignore rule e is active or inactive. The values can be:
|
String | Yes |
| name | Ignore rule name | String | Yes |
| attack | Attack details on which ignore rule is to be applied | Object | No |
| resource | Details of interface on which ignore rule is to be applied | Object | No |
| attacker | Attacker details for ignore rule | Object | No |
| target | Target details for ignore rule | Object | No |
| lastUpdatedByTime | Time when an ignore rule was last updated | Number | No |
| lastUpdatedByUserName | The user by whom the ignore rule was last updated | String | No |
| comment | Comments for ignore rule | String | No |
| ownerDomain | The domain in which the ignore rule is created | String | No |
Details of attack:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| attackName | Names of the attack | String | Yes |
| attackDirection | Direction of the attack. The values can be:
|
String | Yes |
Details of resource:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| resourceId | The id of the interface/resource | Number | No |
| resourceName | Name of the interface | String | Yes (If not specified, default is MATCH ANY) |
| resourceType | Indicated the type of interface on which ignore rule is created. Its values can be:
|
Number | No |
| sensorId | ID of the Sensor on which the rule is applicable | Number | No |
Details of attacker:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| AttackerEndPoint | Attacker rule objects on which ignore rules will be applicable. | String | Yes (Default is Match ANY) |
| AttackerPort | Port type. Its value can be:
|
String | Yes (If not specified default is ANY) |
| AttackerPortNumber |
|
String | Yes (Not applicable for ANY port type) |
Details of target:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| TargetEndPoint | Target rule objects on which ignore rules will be applicable | String | Yes (Default is Match ANY) |
| TargetPort | Port type. Its value can be:
|
String | Yes (If not specified default is ANY) |
| TargetPortNumber |
|
String | Yes (not applicable for ANY port type) |
Note
One of the attacker and target request parameters must be specified.
Query Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| context | Context of the ignore rule. Its values can be:
|
String | Yes (If not specified default is SENSOR) |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| createdResourceId | Rule id of the created ignore rule | Number |
Example
Request
PUT https://<NSM_IP>/sdkapi/domain/0/attackfilter82?context=SENSOR
Payload
{
"state": "ENABLED",
"name": "TEST IGNORE RULE_3",
"attack":
{
"attackName":
[
"0x45d20400"
],
"attackDirection": "INBOUND"
},
"resource":
[
{
"resourceName": "M-2950-1/1A-1B"
}
],
"attacker":
{
"AttackerEndPoint":
[
"0012_0040_0045_src",
"109_110_111_112_src"
],
"AttackerPort": "TCP",
"AttackerPortNumber": "25"
},
"target":
{
"TargetEndPoint":
[
"0012_0040_0045_src",
"118_117_116_116_dest"
],
"TargetPort": "TCP",
"TargetPortNumber": "25"
},
"comment": "Trellix IPS Manager",
}
Response
{
"createdResourceId": 145
}
Example
Request
PUT https://<NSM_IP>/sdkapi/domain/0/attackfilter82?context=NTBA
Payload
{
"state": "ENABLED",
"name": "NTBA IGNORE RULE",
"attack":
{
"attackName":
[
"0x43f00900",
"0x43f00800",
"0x43f00c00"
],
"attackDirection": "ANY"
},
"resource":
[
{
"resourceName": "ntba-nsmapi"
}
],
"attacker":
{
"AttackerEndPoint":
[
"0012_0040_0045_src"
],
"AttackerPort": "UDP",
"AttackerPortNumber": "23"
},
"target":
{
"TargetEndPoint":
[
"00012_0030_0038_dest"
],
"TargetPort": "UDP",
"TargetPortNumber": "23"
},
"comment": "Trellix IPS Manager"
}
Response
{
"createdResourceId": 146
}
Error Information
Following error codes are returned by this URL:
| No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 404 | 1408 | Invalid rule id/provided rule id is not visible this domain |
| 2 | 400 | 1720 | Invalid rule object/rule object is not visible in this domain |
| 3 | 400 | 2513 | Name must only letters, numerical, spaces, commas, periods, hyphen or underscore |
| 4 | 400 | 1437 | Rule name should not be longer than 64 characters |
| 5 | 400 | 1433 | This rule is invalid because it would match all alerts. Please specify at least one alert criterion |
| 6 | 400 | 1434 | Port number must be given for TCP, UDP, TCP_UDP port types. |
| 7 | 400 | 1415 | Port not valid, please enter a number between 1 and 65535 |
| 8 | 400 | 1422 | Resource is not visible in this domain |
| 9 | 400 | 1001 | Rule with same name already exist |
| 10 | 400 | 1435 | The same combination of IPv4 and IPv6 should be used in attacker and target endpoints. |
| 11 | 400 | 1421 | The attacker and target port fields are using an invalid protocol combination. |
| 12 | 400 | 1436 | One of the attacker or target criteria must be specified |