The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Alert Details

Prev Next

This URL is used to retrieve the alert details.

Resource URL

GET /alerts/<alert_uuid>?sensorId=<sensor_id>&manager=<manager_name>

Request Parameters

Query Parameters:

Field Name Description Data Type Mandatory
Alert_uuid Alert uuid Number Yes
sensorId Sensor id Number Yes
manager Name of the Manager. Required in case a multiple Managers are monitored with a single Manager. String No

Response Parameters

Following fields are returned.

Field Name Description Data Type
name Name String
uniqueAlertId Unique alert id String
alertState Alert state String
summary Summary Object
details Details Object
description Description Object

Example

Request

GET https://<NSM_IP>/sdkapi/alerts/6245941293374080682

Response

{
        "name": "DNS: IQUERY Buffer Overflow",
        "uniqueAlertId": "6806386691967877137",
        "alertState": "UnAcknowledged",
        "assignTo": "---",
        "summary": {
            "event": {
                "application": "Not Available",
                "protocol": "telnet",
                "domain": "/My Company",
                "manager": null,
                "device": "vm600-nsmapi-cc",
                "deviceId": "1001",
                "interface": "1-2",
                "matchedPolicy": "Default Prevention",
                "zone": null,
                "vlan": "-10",
                "detection": "Application anomaly",
                "time": "Apr 23, 2020 22:26:13",
                "direction": "Inbound",
                "result": "Inconclusive",
                "attackCount": 1,
                "relevance": "Unknown",
                "alertId": "6806386691964665876"
            },
            "attacker": {
                "ipAddrs": "60.131.8.49",
                "port": 17561,
                "hostName": null,
                "country": null,
                "os": "Microsoft Windows Server 2008",
                "vmName": null,
                "proxyIP": null,
                "user": "Unknown",
                "risk": "N/A",
                "networkObject": "---"
            },
            "target": {
                "ipAddrs": "0.20.209.51",
                "port": 58004,
                "hostName": null,
                "country": null,
                "os": "Microsoft Windows Server 2003 Service Pack 1",
                "vmName": null,
                "proxyIP": null,
                "user": "Unknown",
                "risk": "N/A",
                "networkObject": "---"
            },
            "source": null,
            "destination": null,
            "zoombie": null,
            "cAndcServer": null,
            "fastFluxAgent": null,
            "attackedHIPEndpoint": null,
            "compromisedEndpoint": null
        },
        "details": {
            "matchedSignature": {
                "signatureName": "IQUERY-overflow-iquery.c",
                "signature": {
                    "name": "Signature#1",
                    "conditions": [
                        "condition 1",
                        " dns-request-hdr-opcode == 1 (  unsigned )",
                        "[AND]  dns-request-answer-type == 1 (  unsigned )",
                        "[AND]  dns-request-answer-class == 1 (  unsigned )",
                        "[AND]  dns-request-answer-rdata matches  \"(\\xeb\\x6e\\x5e\\xc6\\x06\\x9a\\x31\\xc9\\x89\\x4e\\x01|\\x80\\xe8\\xd7\\xff\\xff\\xff/bin/sh)\" (  case-sensitive )"
                    ]
                }
            },
            "layer7": null,
            "malwareFile": null,
            "hostSweep": null,
            "portScan": null,
            "fastFlux": null,
            "triggeredComponentAttacks": null,
            "sqlInjection": null,
            "callbackDetectors": null,
            "exceededThreshold": null,
            "communicationRuleMatch": null
        },
        "description": {
            "definition": "BIND is used by most UNIX DNS servers, and implements the Domain Name Service (DNS) protocol. Certain versions of BIND do not properly bounds check a memory copy when responding to an inverse query (IQUERY) request. An improperly or maliciously formatted inverse query in a TCP stream can crash the server or allow an attacker to execute arbitrary code, possibly gaining root privileges.\n\nBuffer overflow vulnerabilities can be exploited to cause a denial of service or enable the execution of arbitrary code with the privileges of the affected server or process.\n\nThe inverse query feature is disabled by default, so only those systems that have been explicitly configured to allow it are vulnerable. Inverse queries can be disabled with little ill effect to prevent this attack.\n\nUpgrade to the latest applicable version of BIND as listed in CERT Advisory CA-98.05. Upgrading to the latest version of BIND 8 is recommended. <br> <br> For SunOS 2.x, apply the necessary patch as listed in Sun Microsystems, Inc. Security Bulletin #00180.\n\nSoftware Packages <br>Internet Software Consortium BIND<ul><ul><li>4.9.6 to 4.9.6</li></ul><ul><li>8.1 to 8.1.1</li></ul></ul>",
            "btp": "Low",
            "rfSB": "Yes",
            "protectionCategory": "[Server Protection/Name Servers]",
            "target": "Server",
            "httpResponseAttack": "No",
            "priority": "High",
            "protocols": "dns",
            "attackCategory": "Exploit",
            "attackSubCategory": "Buffer Overflow",
            "snortEngine": "---",
            "versionAdded": "10.8.1.6",
            "versionUpdated": "10.8.1.6",
            "reference": {
                "nspId": "0x40300200",
                "cveId": "CVE-1999-0009",
                "microsoftId": "",
                "bugtraqId": "134",
                "certId": null,
                "arachNidsId": "",
                "additionInfo": "http://www.cert.org/advisories/CA-98.05.bind_problems.html"
            },
            "signatures": [
                {
                    "name": "Signature#1",
                    "conditions": [
                        "condition 1",
                        " dns-request-hdr-opcode == 1 (  unsigned )",
                        "[AND]  dns-request-answer-type == 1 (  unsigned )",
                        "[AND]  dns-request-answer-class == 1 (  unsigned )",
                        "[AND]  dns-request-answer-rdata matches  \"(\\xeb\\x6e\\x5e\\xc6\\x06\\x9a\\x31\\xc9\\x89\\x4e\\x01|\\x80\\xe8\\xd7\\xff\\xff\\xff/bin/sh)\" (  case-sensitive )"
                    ]
                },
                {
                    "name": "Signature#2",
                    "conditions": [
                        "condition 1",
                        " dns-request-hdr-opcode == 1 (  unsigned )",
                        "[AND]  dns-request-answer-type == 1 (  unsigned )",
                        "[AND]  dns-request-answer-class == 1 (  unsigned )",
                        "[AND]  dns-request-answer-rdata matches  \"(\\xff\\xff\\xff/usr/bin/X11/xterm\\xff-display|\\xe8\\xd7\\xff\\xff\\xff/tmp/hi)\" (  case-sensitive )"
                    ]
                },
                {
                    "name": "Signature#3",
                    "conditions": [
                        "condition 1",
                        " dns-request-hdr-opcode == 1 (  unsigned )",
                        "[AND]  dns-error-code == host-ip-addr-len-too-long (  unsigned )",
                        "[AND THEN] condition 2",
                        "[Any Of]",
                        " System Event Name=\"shellcode-detected-for-arch-i386\" ",
                        "[OR]  System Event Name=\"shellcode-detected-for-arch-sparc\" ",
                        "[OR]  System Event Name=\"shellcode-detected-for-arch-powerpc\" "
                    ]
                },
                {
                    "name": "Signature#4",
                    "conditions": [
                        "condition 1",
                        " dns-request-hdr-opcode == 1 (  unsigned )",
                        "[AND]  dns-error-code == iquery-overflow (  unsigned )",
                        "[AND THEN] condition 2",
                        "[Any Of]",
                        " System Event Name=\"shellcode-detected-for-arch-i386\" ",
                        "[OR]  System Event Name=\"shellcode-detected-for-arch-sparc\" ",
                        "[OR]  System Event Name=\"shellcode-detected-for-arch-powerpc\" "
                    ]
                },
                {
                    "name": "Signature#5",
                    "conditions": [
                        "condition 1",
                        " dns-request-hdr-opcode == 1 (  unsigned )",
                        "[AND]  dns-error-code == iquery-overflow (  unsigned )"
                    ]
                }
            ],
            "componentAttacks": [],
            "comments": {
                "comments": "",
                "availabeToChildDomains": true,
                "parentDomainComments": null
            }
        }
    } 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 9803 Invalid alert id
2 404 9803 Sensor id is required
3 404 9803 Manager name is required