The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get an Attack Filter

Prev Next

This URL gets the details of an attack filter.

Resource URL

GET /attackfilter/<attackfilter_id>

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

attackfilter_id

Attack filter id

Number

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

name

Attack filter name

String

attackFilterId

Attack filter id

Number

Description

Description

String

DomainId

Id of domain to which this attack filter belongs to

Number

LastModTs

Last modified timestamp

String

Type

Attack filter type, can be "IPV_4" / "IPV_6" / "TCP_UDP_PORT" / "IPV_4_TCP_UDP_PORT" / "IPV_6_TCP_UDP_PORT"

String

MatchCriteria

Attack filter exclusion

Object

Details of MatchCriteria:

Field Name

Description

Data Type

Exclusion

List of IP - port exclusions

Array

Details of object in Exclusion (depends on the Type defined):

Field Name

Description

Data Type

Ip

IPv4 or IPv6 IP

Object

Port

TCP / UDP port

Object

Details of Ip:

Field Name

Description

Data Type

srcStart

Source start IP

String

srcEnd

Source end IP

String

destStart

Destination start IP

String

destEnd

Destination end IP

String

srcMode

Source IP mode, can be "ANY_IP" / "ANY_EXTERNAL_IP" / "ANY_INTERNAL_IP" / "RANGE_IP" / "SINGLE_IP"

String

destMode

Destination IP mode, can be "ANY_IP" / "ANY_EXTERNAL_IP" / "ANY_INTERNAL_IP" / "RANGE_IP" / "SINGLE_IP"

String

Details of port:

Field Name

Description

Data Type

srcPort

Source port

String

destPort

Destination port

String

srcPortMode

Source port mode, can be "ANY_PORT" / "TCP_OR_UDP" / "TCP" / "UDP"

String

destPortMode

Destination port mode, can be "ANY_PORT" / "TCP_OR_UDP" / "TCP" / "UDP"

String

Example

Request

GET https://<NSM_IP>/sdkapi/ attackfilter/420

Response

{
   "DomainId": 0, 
   "MatchCriteria": {
      "Exclusion": [
         {
            "Ip": {}, 
            "Port": {
               "srcPortMode": "TCP", 
               "srcPort": "85", 
               "destPort": "89", 
               "destPortMode": "TCP"
            }
         }
      ]
   }, 
   "LastModTs": "2012-07-24 00:19:00", 
   "attackFilterId": 420, 
   "Type": "TCP_UDP_PORT", 
   "name": "test2"
}

Error Information

Following error code isreturned by this URL:

S.No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1408

Invalid attack filter id