The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create an Ignore Rule

Prev Next

This URL creates a new ignore rule.

Resource URL

POST /domain/<domainId>/attackfilter82

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
domain_id Domain id Number Yes

Payload Request Parameters:

Field Name Description Data Type Mandatory
attackFilter The details of the ignore rules created within the given domain Object Yes

Details of attackFilter:

Field Name Description Data Type Mandatory
id The unique identifier for an ignore rule Number No
state Field to indicate whether an ignore rule e is active or inactive. The values can be:
  • ENABLED
  • DISABLED
String Yes
name Ignore rule name String Yes
attack Attack details on which ignore rule is to be applied Object No
resource Details of interface on which ignore rule is to be applied Object No
attacker Attacker details for ignore rule Object No
target Target details for ignore rule Object No
lastUpdatedByTime Time when an ignore rule was last updated Number No
lastUpdatedByUserName The user by whom the ignore rule was last updated String No
comment Comments for ignore rule String No
ownerDomain The domain in which the ignore rule is created String No

Details of attack:

Field Name Description Data Type Mandatory
attackName Names of the attack String Yes
attackDirection Direction of the attack. The values can be:
  • INBOUND
  • OUTBOUND
  • ANY
String Yes

Details of resource:

Field Name Description Data Type Mandatory
resourceId The id of the interface/resource Number No
resourceName Name of the interface String Yes (If not specified, default is MATCH ANY)
resourceType Indicated the type of interface on which ignore rule is created. Its values can be:
  • 0: Resource type is domain (for domain level rules)
  • 1: Resource type is Sensor (for sensor level rules)
  • 2: Resource type is Vids (for interface and sub-interface level rules)
  • 3: Resource type is NTBA_ZONE (for rules defined for NTBA inside and outside zones)
  • 4: Resource type is NTBA_SENSOR (for rules at NTBA level)
  • 5: Resource type is NTBA_DOMAIN
Number No
sensorId ID of the Sensor on which the rule is applicable Number No

Details of attacker:

Field Name Description Data Type Mandatory
AttackerEndPoint Attacker rule objects on which ignore rules will be applicable. String Yes (Default is Match ANY)
AttackerPort Port type. Its value can be:
  • TCP
  • UDP
  • TCP_UDP
  • ANY
String Yes (If not specified default is ANY)
AttackerPortNumber
  • Port numbers
String Yes (Not applicable for ANY port type)

Details of target:

Field Name Description Data Type Mandatory
TargetEndPoint Target rule objects on which ignore rules will be applicable String Yes (Default is Match ANY)
TargetPort Port type. Its value can be:
  • TCP
  • UDP
  • TCP_UDP
  • ANY
String Yes (If not specified default is ANY)
TargetPortNumber
  • Port numbers
String Yes (not applicable for ANY port type)

Note

One of the attacker and target request parameters must be specified.

Query Parameters:

Field Name Description Data Type Mandatory
context Context of the ignore rule. Its values can be:
  • NTBA
  • SENSOR
String Yes (If not specified default is SENSOR)

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
createdResourceId Rule id of the created ignore rule Number

Example

Request

PUT https://<NSM_IP>/sdkapi/domain/0/attackfilter82?context=SENSOR

Payload

{
       "state": "ENABLED",
       "name": "TEST IGNORE RULE_3",
       "attack":
       {
           "attackName":
           [
               "0x45d20400"
           ],
           "attackDirection": "INBOUND"
       },
       "resource":
       [
           {
               "resourceName": "M-2950-1/1A-1B"
           }
       ],
       "attacker":
       {
           "AttackerEndPoint":
           [
               "0012_0040_0045_src",
               "109_110_111_112_src"
           ],
           "AttackerPort": "TCP",
           "AttackerPortNumber": "25"
       },
       "target":
       {
           "TargetEndPoint":
           [
               "0012_0040_0045_src",
               "118_117_116_116_dest"
           ],
           "TargetPort": "TCP",
           "TargetPortNumber": "25"
       },
       "comment": "Trellix IPS Manager",
    } 

Response

{
   "createdResourceId": 145
} 
 

Example

Request

PUT https://<NSM_IP>/sdkapi/domain/0/attackfilter82?context=NTBA

Payload

{
         "state": "ENABLED",
         "name": "NTBA IGNORE RULE",
         "attack":
          {
              "attackName":
              [
                  "0x43f00900",
                  "0x43f00800",
                  "0x43f00c00"
              ],
              "attackDirection": "ANY"
          },
          "resource":
           [
               {
                   "resourceName": "ntba-nsmapi"
               }
           ],
           "attacker":
           {
               "AttackerEndPoint":
               [
                   "0012_0040_0045_src"
               ],
               "AttackerPort": "UDP",
               "AttackerPortNumber": "23"
           },
           "target":
           {
               "TargetEndPoint":
               [
                   "00012_0030_0038_dest"
               ],
               "TargetPort": "UDP",
               "TargetPortNumber": "23"
           },
           "comment": "Trellix IPS Manager"
       } 

Response

{
   "createdResourceId": 146
} 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1408 Invalid rule id/provided rule id is not visible this domain
2 400 1720 Invalid rule object/rule object is not visible in this domain
3 400 2513 Name must only letters, numerical, spaces, commas, periods, hyphen or underscore
4 400 1437 Rule name should not be longer than 64 characters
5 400 1433 This rule is invalid because it would match all alerts. Please specify at least one alert criterion
6 400 1434 Port number must be given for TCP, UDP, TCP_UDP port types.
7 400 1415 Port not valid, please enter a number between 1 and 65535
8 400 1422 Resource is not visible in this domain
9 400 1001 Rule with same name already exist
10 400 1435 The same combination of IPv4 and IPv6 should be used in attacker and target endpoints.
11 400 1421 The attacker and target port fields are using an invalid protocol combination.
12 400 1436 One of the attacker or target criteria must be specified