The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Alert Details

Prev Next

This URL is used to retrieve the alert details.

Resource URL

GET /alerts/<alert_uuid>?sensorId=<sensor_id>&manager=<manager_name>

Request Parameters

Query Parameters:

Field Name

Description

Data Type

Mandatory

Alert_uuid

Alert uuid

Number

Yes

sensorId

Sensor id

Number

Yes

manager

Name of the Manager. Required in case a multiple Managers are monitored with a single Manager.

String

No

Response Parameters

Following fields are returned.

Field Name

Description

Data Type

name

Name

String

uniqueAlertId

Unique alert id

String

alertState

Alert state

String

summary

Summary

Object

details

Details

Object

description

Description

Object

Example

Request

GET https://<NSM_IP>/sdkapi/alerts/6245941293374080682

Response

{
        "name": "DNS: IQUERY Buffer Overflow",
        "uniqueAlertId": "6806386691967877137",
        "alertState": "UnAcknowledged",
        "assignTo": "---",
        "summary": {
            "event": {
                "application": "Not Available",
                "protocol": "telnet",
                "domain": "/My Company",
                "manager": null,
                "device": "vm600-nsmapi-cc",
                "deviceId": "1001",
                "interface": "1-2",
                "matchedPolicy": "Default Prevention",
                "zone": null,
                "vlan": "-10",
                "detection": "Application anomaly",
                "time": "Apr 23, 2020 22:26:13",
                "direction": "Inbound",
                "result": "Inconclusive",
                "attackCount": 1,
                "relevance": "Unknown",
                "alertId": "6806386691964665876"
            },
            "attacker": {
                "ipAddrs": "60.131.8.49",
                "port": 17561,
                "hostName": null,
                "country": null,
                "os": "Microsoft Windows Server 2008",
                "vmName": null,
                "proxyIP": null,
                "user": "Unknown",
                "risk": "N/A",
                "networkObject": "---"
            },
            "target": {
                "ipAddrs": "0.20.209.51",
                "port": 58004,
                "hostName": null,
                "country": null,
                "os": "Microsoft Windows Server 2003 Service Pack 1",
                "vmName": null,
                "proxyIP": null,
                "user": "Unknown",
                "risk": "N/A",
                "networkObject": "---"
            },
            "source": null,
            "destination": null,
            "zoombie": null,
            "cAndcServer": null,
            "fastFluxAgent": null,
            "attackedHIPEndpoint": null,
            "compromisedEndpoint": null
        },
        "details": {
            "matchedSignature": {
                "signatureName": "IQUERY-overflow-iquery.c",
                "signature": {
                    "name": "Signature#1",
                    "conditions": [
                        "condition 1",
                        " dns-request-hdr-opcode == 1 (  unsigned )",
                        "[AND]  dns-request-answer-type == 1 (  unsigned )",
                        "[AND]  dns-request-answer-class == 1 (  unsigned )",
                        "[AND]  dns-request-answer-rdata matches  \"(\\xeb\\x6e\\x5e\\xc6\\x06\\x9a\\x31\\xc9\\x89\\x4e\\x01|\\x80\\xe8\\xd7\\xff\\xff\\xff/bin/sh)\" (  case-sensitive )"
                    ]
                }
            },
            "layer7": null,
            "malwareFile": null,
            "hostSweep": null,
            "portScan": null,
            "fastFlux": null,
            "triggeredComponentAttacks": null,
            "sqlInjection": null,
            "callbackDetectors": null,
            "exceededThreshold": null,
            "communicationRuleMatch": null
        },
        "description": {
            "definition": "BIND is used by most UNIX DNS servers, and implements the Domain Name Service (DNS) protocol. Certain versions of BIND do not properly bounds check a memory copy when responding to an inverse query (IQUERY) request. An improperly or maliciously formatted inverse query in a TCP stream can crash the server or allow an attacker to execute arbitrary code, possibly gaining root privileges.\n\nBuffer overflow vulnerabilities can be exploited to cause a denial of service or enable the execution of arbitrary code with the privileges of the affected server or process.\n\nThe inverse query feature is disabled by default, so only those systems that have been explicitly configured to allow it are vulnerable. Inverse queries can be disabled with little ill effect to prevent this attack.\n\nUpgrade to the latest applicable version of BIND as listed in CERT Advisory CA-98.05. Upgrading to the latest version of BIND 8 is recommended. <br> <br> For SunOS 2.x, apply the necessary patch as listed in Sun Microsystems, Inc. Security Bulletin #00180.\n\nSoftware Packages <br>Internet Software Consortium BIND<ul><ul><li>4.9.6 to 4.9.6</li></ul><ul><li>8.1 to 8.1.1</li></ul></ul>",
            "btp": "Low",
            "rfSB": "Yes",
            "protectionCategory": "[Server Protection/Name Servers]",
            "target": "Server",
            "httpResponseAttack": "No",
            "priority": "High",
            "protocols": "dns",
            "attackCategory": "Exploit",
            "attackSubCategory": "Buffer Overflow",
            "snortEngine": "---",
            "versionAdded": "10.8.1.6",
            "versionUpdated": "10.8.1.6",
            "reference": {
                "nspId": "0x40300200",
                "cveId": "CVE-1999-0009",
                "microsoftId": "",
                "bugtraqId": "134",
                "certId": null,
                "arachNidsId": "",
                "additionInfo": "http://www.cert.org/advisories/CA-98.05.bind_problems.html"
            },
            "signatures": [
                {
                    "name": "Signature#1",
                    "conditions": [
                        "condition 1",
                        " dns-request-hdr-opcode == 1 (  unsigned )",
                        "[AND]  dns-request-answer-type == 1 (  unsigned )",
                        "[AND]  dns-request-answer-class == 1 (  unsigned )",
                        "[AND]  dns-request-answer-rdata matches  \"(\\xeb\\x6e\\x5e\\xc6\\x06\\x9a\\x31\\xc9\\x89\\x4e\\x01|\\x80\\xe8\\xd7\\xff\\xff\\xff/bin/sh)\" (  case-sensitive )"
                    ]
                },
                {
                    "name": "Signature#2",
                    "conditions": [
                        "condition 1",
                        " dns-request-hdr-opcode == 1 (  unsigned )",
                        "[AND]  dns-request-answer-type == 1 (  unsigned )",
                        "[AND]  dns-request-answer-class == 1 (  unsigned )",
                        "[AND]  dns-request-answer-rdata matches  \"(\\xff\\xff\\xff/usr/bin/X11/xterm\\xff-display|\\xe8\\xd7\\xff\\xff\\xff/tmp/hi)\" (  case-sensitive )"
                    ]
                },
                {
                    "name": "Signature#3",
                    "conditions": [
                        "condition 1",
                        " dns-request-hdr-opcode == 1 (  unsigned )",
                        "[AND]  dns-error-code == host-ip-addr-len-too-long (  unsigned )",
                        "[AND THEN] condition 2",
                        "[Any Of]",
                        " System Event Name=\"shellcode-detected-for-arch-i386\" ",
                        "[OR]  System Event Name=\"shellcode-detected-for-arch-sparc\" ",
                        "[OR]  System Event Name=\"shellcode-detected-for-arch-powerpc\" "
                    ]
                },
                {
                    "name": "Signature#4",
                    "conditions": [
                        "condition 1",
                        " dns-request-hdr-opcode == 1 (  unsigned )",
                        "[AND]  dns-error-code == iquery-overflow (  unsigned )",
                        "[AND THEN] condition 2",
                        "[Any Of]",
                        " System Event Name=\"shellcode-detected-for-arch-i386\" ",
                        "[OR]  System Event Name=\"shellcode-detected-for-arch-sparc\" ",
                        "[OR]  System Event Name=\"shellcode-detected-for-arch-powerpc\" "
                    ]
                },
                {
                    "name": "Signature#5",
                    "conditions": [
                        "condition 1",
                        " dns-request-hdr-opcode == 1 (  unsigned )",
                        "[AND]  dns-error-code == iquery-overflow (  unsigned )"
                    ]
                }
            ],
            "componentAttacks": [],
            "comments": {
                "comments": "",
                "availabeToChildDomains": true,
                "parentDomainComments": null
            }
        }
    }

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

9803

Invalid alert id

2

404

9803

Sensor id is required

3

404

9803

Manager name is required