The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Host Summary

Prev Next

This URL retrieves the host analysis summary for given IP address for the time frame.

Resource URL

GET /networkforensics/<ipaddress>?startime=<start_time>&&duration=<duration>&&ntba=<ntba_id>

URL Parameters: ipaddress

Query Parameter1: starttime=

Date in the format yyyy-MM-dd HH:mm

Query Parameter 2: duration=

  • NEXT_60_SECONDS
  • NEXT_5_MINUTES
  • NEXT_60_MINUTES
  • NEXT_30_MINUTES

Query Parameter 3: ntba id

Request Parameters

Query Request Parameters:

Field Name Description Data Type Mandatory
starttime Start time for analysis String No
duration Duration String No
Ntba_id NTBA id Number No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
NetworkForensicsSummary Summary of IP address Object

Details of fields in NetworkForensicsSummary:

Field Name Description Data Type
endpointSummary Endpoint summary Object
ClientConnections Client connections Object
ServerConnections Server connections Object

Details of fields in endpointSummary:

Field Name Description Data Type
ipAddress IP address String
analysisWindow Analysis window String
zone Zone String
country Country String
etf Etf String
dataSource Data source String

Details of fields in ClientConnections:

Field Name Description Data Type
connections Connections String
applications Applications String
endpointExecutables Endpoint executables String
tcpServices Server connections String
tcpHighPorts TCP high ports String
udpServices UDP services String
udpHighPorts UDP high ports String

Details of ServerConnections:

Field Name Description Data Type
connections Connections String
applications Applications String
tcpServices TCP services String
tcpHighPorts TCP high ports String
udpServices UDP services String
udpHighPorts UDP high ports String

Example

Request

GET https://<NSM_IP>/sdkapi/networkforensics /1.1.1.1/?duration=NEXT_30_MINUTES&&starttime=2012-APR-20 12:15&ntba=1001

Response

 {
       " endpointSummary ":
           {
               " analysisWindow ": "",
               " zone ": "South",
               " country ": "India",
               " dataSource ": "Allowed",
               " ipAddress ": “”
           
         }  
       " ClientConnections ":
           {
               " connections ": "10-Aug-2014 12:00",
               " applications ": "",
               " endpointExecutables ": "BitTorrent.exe"           
         }  
       " ServerConnections ":
           {
               " connections ": "10-Aug-2014 12:00",
               " applications ": "",           
         }  
} 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 400 4301 Invalid duration
2 400 4302 Invalid time format
3 400 5000 Invalid IP address