The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Host Summary

Prev Next

This URL retrieves the host analysis summary for given IP address for the time frame.

Resource URL

GET /networkforensics/<ipaddress>?startime=<start_time>&&duration=<duration>&&ntba=<ntba_id>

URL Parameters: ipaddress

Query Parameter1: starttime=

Date in the format yyyy-MM-dd HH:mm

Query Parameter 2: duration=

  • NEXT_60_SECONDS

  • NEXT_5_MINUTES

  • NEXT_60_MINUTES

  • NEXT_30_MINUTES

Query Parameter 3: ntba id

Request Parameters

Query Request Parameters:

Field Name

Description

Data Type

Mandatory

starttime

Start time for analysis

String

No

duration

Duration

String

No

Ntba_id

NTBA id

Number

No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

NetworkForensicsSummary

Summary of IP address

Object

Details of fields in NetworkForensicsSummary:

Field Name

Description

Data Type

endpointSummary

Endpoint summary

Object

ClientConnections

Client connections

Object

ServerConnections

Server connections

Object

Details of fields in endpointSummary:

Field Name

Description

Data Type

ipAddress

IP address

String

analysisWindow

Analysis window

String

zone

Zone

String

country

Country

String

etf

Etf

String

dataSource

Data source

String

Details of fields in ClientConnections:

Field Name

Description

Data Type

connections

Connections

String

applications

Applications

String

endpointExecutables

Endpoint executables

String

tcpServices

Server connections

String

tcpHighPorts

TCP high ports

String

udpServices

UDP services

String

udpHighPorts

UDP high ports

String

Details of ServerConnections:

Field Name

Description

Data Type

connections

Connections

String

applications

Applications

String

tcpServices

TCP services

String

tcpHighPorts

TCP high ports

String

udpServices

UDP services

String

udpHighPorts

UDP high ports

String

Example

Request

GET https://<NSM_IP>/sdkapi/networkforensics /1.1.1.1/?duration=NEXT_30_MINUTES&&starttime=2012-APR-20 12:15&ntba=1001

Response

    {
       " endpointSummary ":
           {
               " analysisWindow ": "",
               " zone ": "South",
               " country ": "India",
               " dataSource ": "Allowed",
               " ipAddress ": “”
           
         }  
       " ClientConnections ":
           {
               " connections ": "10-Aug-2014 12:00",
               " applications ": "",
               " endpointExecutables ": "BitTorrent.exe"           
         }  
       " ServerConnections ":
           {
               " connections ": "10-Aug-2014 12:00",
               " applications ": "",           
         }  
}

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

400

4301

Invalid duration

2

400

4302

Invalid time format

3

400

5000

Invalid IP address