The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get All Alerts

Prev Next

This URL retrieves all alerts.

Resource URL

GET /alerts? domainId=<domain_id>&includeChildDomain=<true/false>&alertstate=<state>&timeperiod=<timeperiod>&startime=<start_time>&endtime=<endBtime>&search=<search_string> &page=<page>&filter=<filterBvalue>

Request Parameters

Query Parameters:

Field Name Description Data Type Mandatory
alertstate Alert state, values allowed are, ANY/Acknowledged/Unacknowledged String No
timeperiod Time period, allowed values are
  • LAST_5_MINUTES
  • Last_1_HOUR
  • LAST_6_HOURS
  • LAST_12_HOURS
  • LAST_24_HOURS
  • LAST_7_DAYS
  • LAST_14_DAYS
  • CUSTOM
String No
starttime Start time String No
endtime End time String No
Page Next/Previous String No
domainId Domain ID. Default value is 0. Number Yes
includeChildDomain Chooses to include child domain or not. Default value is true. Boolean Yes
search Search String No
Filter Filter on following column is allowed

name, assignTo, application, layer7Data, result, attackCount, relevance, alertId, direction, device, domain, interface, attackSeverity, nspId, btp, attackCategory, malwarefileName, malwarefileHash, malwareName, malwareConfidence, malwareEngine ,executableName, executableHash, executableConfidenceName, attackerIPAddress, attackerPort, attackerRisk, attackerProxyIP, attackerHostname, targetIPAddress, targetPort, targetRisk, targetProxyIP, targetHostname, botnetFamily

Ex: name:Malware;direction:Inbound,Outbound;attackcount:>3,<4

String No

Response Parameters

Following fields are returned.

Field Name Description Data Type
totalAlertsCount Total alerts count Number
retrievedAlertsCount Retrieved alerts count Number
alertsList List of alerts ObjectList

Details of alerts:

Field Name Description Data Type
name Alert name String
uniqueAlertId Unique alert id Number
alertState List of alerts Object
assignTo Assignment String
attackSeverity Attack severity String
event Event details Object
attack Attack details Object
attacker Attacker details Object
target Target details Object
malwareFile Malware file Object
endpointExcutable Endpoint executable Object
detection Detection Object
application Application string String
layer7Data Layer 7 information String

Details of event:

Field Name Description Data Type
time Time String
direction Direction Number
result Result String
attackCount Attack count String
relevance Relevance String
alertId Alert id Number
nspId NSP id String
btp Btp String
attackCategory Attack category String

Details of attacker/target:

Field Name Description Data Type
ipAddrs IP address String
port Port String
hostName Host name String
country Country String
os OS String
vmName VM name String
proxyIP Proxy IP String
user User String
risk Risk String
networkObject Network object String

Details of malwareFile:

Field Name Description Data Type
fileName File name String
fileHash File hash String
malwareName Malware name String
malwareConfidence Malware confidence String
engine Engine String
size Size String

Details of EndpointExecutable:

Field Name Description Data Type
name Name String
hash Hash String
malwareConfidence Malware confidence String

Example

Request

GET https://<NSM_IP>/sdkapi/alerts?fromalert=1334242&page=next&timeperiod=custom&starttime=10/10/2015 12:00&endtime=01/12/2015 12:00

Response

"totalAlertsCount": 824917,
    "retrievedAlertsCount": 1000,
    "alertsList":
    [
        {
            "name": "DNS: New Dataloc Test Attack 8-3 (16 bytes)",
            "uniqueAlertId": "6245941293374082717",
            "alertState": "UnAcknowledged",
            "assignTo": "",
            "attackSeverity": "Medium",
            "event":
            {
                "time": "Jan 04, 2016 16:24:4",
                "direction": "Outbound",
                "result": "Inconclusive",
                "attackCount": 1,
                "relevance": "Unknown",
                "alertId": "1383009720294233669"
            },
            "attack":
            {
                "nspId": "0x40307a00",
                "btp": "Low",
                "attackCategory": "Exploit"
            },
            "attacker":
            {
                "ipAddrs": "1.1.1.10",
                "port": 58719,
                "hostName": "",
                "country": null,
                "os": null,
                "vmName": null,
                "proxyIP": "",
                "user": null,
                "risk": "Minimal Risk",
                "networkObject": null
            },
            "target":
            {
                "ipAddrs": "1.1.1.9",
                "port": 53,
                "hostName": "",
                "country": null,
                "os": null,
                "vmName": null,
                "proxyIP": "",
                "user": null,
                "risk": "Minimal Risk",
                "networkObject": null
            },
            "malwareFile":
            {
                "fileName": "",
                "fileHash": "",
                "malwareName": "",
                "malwareConfidence": "",
                "engine": "",
                "size": null
            },
            "endpointExcutable":
            {
                "name": "",
                "hash": "",
                "malwareConfidence": ""
            },
            "detection":
            {
                "domain": "/My Company",
                "device": "prabu-6050",
                "interface": "5A-5B"
            },
            "application": "DNS",
            "layer7Data": ""
        },
        {
            "name": "DNS: New Dataloc Test Attack 8-3 (16 bytes)",
            "uniqueAlertId": "6245941293374082716",
            "alertState": "UnAcknowledged",
            "assignTo": "",
            "attackSeverity": "Medium",
            "event":
            {
                "time": "Jan 04, 2016 16:24:4",
                "direction": "Outbound",
                "result": "Inconclusive",
                "attackCount": 1,
                "relevance": "Unknown",
                "alertId": "1383009720294233668"
            },
            "attack":
            {
                "nspId": "0x40307a00",
                "btp": "Low",
                "attackCategory": "Exploit"
            },
            "attacker":
            {
                "ipAddrs": "1.1.1.10",
                "port": 58719,
                "hostName": "",
                "country": null,
                "os": null,
                "vmName": null,
                "proxyIP": "",
                "user": null,
                "risk": "Minimal Risk",
                "networkObject": null
            },
            "target":
            {
                "ipAddrs": "1.1.1.9",
                "port": 53,
                "hostName": "",
                "country": null,
                "os": null,
                "vmName": null,
                "proxyIP": "",
                "user": null,
                "risk": "Minimal Risk",
                "networkObject": null
            },
            "malwareFile":
            {
                "fileName": "",
                "fileHash": "",
                "malwareName": "",
                "malwareConfidence": "",
                "engine": "",
                "size": null
            },
            "endpointExcutable":
            {
                "name": "",
                "hash": "",
                "malwareConfidence": ""
            },
            "detection":
            {
                "domain": "/My Company",
                "device": "prabu-6050",
                "interface": "5A-5B"
            },
            "application": "DNS",
            "layer7Data": ""
        }
]
} 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 3704 Invalid filter value
2 404 9803 Sensor id is required
3 404 9803 Manager name is required