The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get an Attack Filter

Prev Next

This URL gets the details of an attack filter.

Resource URL

GET /attackfilter/<attackfilter_id>

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
attackfilter_id Attack filter id Number Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
name Attack filter name String
attackFilterId Attack filter id Number
Description Description String
DomainId Id of domain to which this attack filter belongs to Number
LastModTs Last modified timestamp String
Type Attack filter type, can be "IPV_4" / "IPV_6" / "TCP_UDP_PORT" / "IPV_4_TCP_UDP_PORT" / "IPV_6_TCP_UDP_PORT" String
MatchCriteria Attack filter exclusion Object

Details of MatchCriteria:

Field Name Description Data Type
Exclusion List of IP - port exclusions Array

Details of object in Exclusion (depends on the Type defined):

Field Name Description Data Type
Ip IPv4 or IPv6 IP Object
Port TCP / UDP port Object

Details of Ip:

Field Name Description Data Type
srcStart Source start IP String
srcEnd Source end IP String
destStart Destination start IP String
destEnd Destination end IP String
srcMode Source IP mode, can be "ANY_IP" / "ANY_EXTERNAL_IP" / "ANY_INTERNAL_IP" / "RANGE_IP" / "SINGLE_IP" String
destMode Destination IP mode, can be "ANY_IP" / "ANY_EXTERNAL_IP" / "ANY_INTERNAL_IP" / "RANGE_IP" / "SINGLE_IP" String

Details of port:

Field Name Description Data Type
srcPort Source port String
destPort Destination port String
srcPortMode Source port mode, can be "ANY_PORT" / "TCP_OR_UDP" / "TCP" / "UDP" String
destPortMode Destination port mode, can be "ANY_PORT" / "TCP_OR_UDP" / "TCP" / "UDP" String

Example

Request

GET https://%3CNSM_IP%3E/sdkapi/%20attackfilter/420

Response

{
   "DomainId": 0, 
   "MatchCriteria": {
      "Exclusion": [
         {
            "Ip": {}, 
            "Port": {
               "srcPortMode": "TCP", 
               "srcPort": "85", 
               "destPort": "89", 
               "destPortMode": "TCP"
            }
         }
      ]
   }, 
   "LastModTs": "2012-07-24 00:19:00", 
   "attackFilterId": 420, 
   "Type": "TCP_UDP_PORT", 
   "name": "test2"
} 
 

Error Information

Following error code isreturned by this URL:

S.No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1408 Invalid attack filter id