The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get IPS Policy Details

Prev Next

This URL gets the policy details (including attack set and response actions) for the specific IPS policy.

Resource URL

GET /ipspolicy/<policy_id>

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

policy_id

IPS policy id

Number

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

PolicyDescriptor

Baseline IPS policy details

Object

Details of PolicyDescriptor:

Field Name

Description

Data Type

PolicyName

Baseline IPS policy name

String

Description

Policy description

String

IsVisibleToChildren

Is policy visible to child domain

Boolean

InboundRuleSet

Inbound policy rule set

String

OutboundRuleSet

Outbound policy rule set

String

AttackCategory

Attack category

Object

OutboundAttackCategory

Outbound attack category

Object

DosPolicy

DoS policy

Object

DosResponseSensitivityLevel

DoS response sensitivity level

Number

IsEditable

Is policy editable

Boolean

Timestamp

Time stamp at which the policy was added

String

VersionNum

Policy version number

Number

IsLightWeightPolicy

Is light weight policy configured

Boolean

Details of object in AttackCategory:

Field Name

Description

Data Type

ExpolitAttackList

List of exploit attacks

Array

Details of object in ExpolitAttackList:

Field Name

Description

Data Type

attackName

Attack name

String

nspId

NSP id of the attack

String

severity

Attack severity, number between 0 & 9

Number

isSeverityCustomized

Is attack severity customized

Boolean

isEnabled

Is attack enabled

Boolean

isAlertCustomized

Is alert customized

Boolean

isRecommendedForSmartBlocking

Is attack recommended for smart blocking

Boolean

AttackResponse

Attack response

Object

notification

Notifications configured

Object

protocolList

List of protocols

Array

applicationsImpactedList

List of applications impacted

Array

attackVector

List of attack vectors

Array

benignTriggerProbability

Attack benign trigger probability

String

target

Attack target, can be "Server" or "Client"

String

blockingType

Blocking type, can be "Attack Packet"

String

subCategory

Attack sub category

String

direction

Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH"

String

isAttackCustomized

Is attack customized

Boolean

Details of object in AttackResponse:

Field Name

Description

Data Type

TCPReset

TCP reset option, can be “DISABLED” / “SOURCE” / “DESTINATION” / “BOTH”

String

isTCPResetCustomized

Is TCP reset customized

Boolean

isICMPSend

Send ICMP host unreachable to Source

Boolean

isICMPSendCustomized

Send ICMP host unreachable to Source customized

Boolean

mcafeeNACNotification

NAC notification configured, can be “DISABLED” / “ALL_HOSTS” / “MCAFEE_NAC_UNMANAGED_HOSTS”

String

isMcafeeNACNotificationEnabled

Is NAC notification enabled

Boolean

isQuarantineCustomized

Is quarantine customized

Boolean

isRemediateEnabled

Is remediate enabled

Boolean

blockingOption

Blocking option configured, can be “DISABLE” / “ENABLE” / “ENABLE_SMART_BLOCKING”

String

isBlockingOptionCustomized

Is blocking option customized

Boolean

isCapturedPrior

Should application data be captured prior to attack

Boolean

isCapturedPriorCustomized

Should application data be captured prior to attack customized

Boolean

action

Action to be taken on attack, can be “DO_NOTHING” / “SEND_ALERT_AND_LOG_PACKETS” / “SEND_ALERT_ONLY”

String

isLogCustomized

Is logging customized

Boolean

flow

Customixe flow, can be “SINGLE_FLOW” / “FORENSIC_ANALYSIS”

String

isFlowCustomized

Customize flow type

Boolean

isNbytesCustomized

Is logging N bytes in each packet customized

Boolean

numberOfBytesInEachPacket

Number of bytes to be logged in each packet

Object

loggingDuration

Packet logging duration

Object

TimeStamp

Time stamp

String

Details of object in numberOfBytesInEachPacket (Can be either of the below mentioned):

Field Name

Description

Data Type

LogEntirePacket

Log entire packet

Object

CaptureNBytes

Capture N bytes

Object

Details of object in CaptureNBytes:

Field Name

Description

Data Type

NumberOfBytes

Number of bytes to log

Number

Details of object in loggingDuration (Can be either of the below mentioned):

Field Name

Description

Data Type

AttackPacketOnly

Log attack packet only

Object

CaptureNPackets

Capture N packets

Object

CaptureTimeDuration

Capture for a time duration

Object

RestOfFlow

Capture rest of flow

Object

Details of object in CaptureNPackets:

Field Name

Description

Data Type

npackets

Log n packets

Number

Details of object in CaptureTimeDuration:

Field Name

Description

Data Type

time

Capture time

String

timeUnit

Time unit, can be "SECONDS" / "MINUTES" / "HOURS" / "DAYS"

String

Details of object in notification:

Field Name

Description

Data Type

isEmail

Is notification configured through email

Boolean

isPager

Is notification configured through pager

Boolean

isScript

Is notification configured through script

Boolean

isAutoAck

Is notification configured through auto ack

Boolean

isSnmp

Is notification configured through SNMP

Boolean

isSyslog

Is notification configured through syslog

Boolean

isEmailCustomized

Is notification through email customized

Boolean

isPagerCustomized

Is notification through pager customized

Boolean

isScriptCustomized

Is notification through script customized

Boolean

isAutoAckCustomized

Is notification through auto ack customized

Boolean

isSnmpCustomized

Is notification through SNMP customized

Boolean

isSyslogCustomized

Is notification through syslog customized

Boolean

Details of object in DosPolicy:

Field Name

Description

Data Type

LearningAttack

List of learning attacks

Array

ThresholdAttack

List of threshold attacks

Array

TimeStamp

Time stamp

String

Details of object in LearningAttack:

Field Name

Description

Data Type

attackName

Attack name

String

nspId

NSP ID of the attack

String

isSeverityCustomized

Is attack severity customized

Boolean

severity

Attack severity, number between 0 & 9

Number

isBlockingSettingCustomized

Is blocking customized

Boolean

isDropPacket

Drop DoS attack packets of this attack type when detected

Boolean

isAlertCustomized

Is alert customized

Boolean

isSendAlertToManager

Is alert notification to be sent to Manager configured

String

timeStamp

Time stamp

String

direction

Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH"

String

notification

Notification to be sent via

Object

isAttackCustomized

Is DoS learning attack customized

Boolean

Details of object in ThresholdAttack:

Field Name

Description

Data Type

attackName

Attack name

String

nspId

NSP id of the attack

String

isSeverityCustomized

Is attack severity customized

Boolean

severity

Attack severity, number between 0 & 9

Number

isThresholdValueCustomized

Is threshold value customized

Boolean

isThresholdDurationCustomized

is threshold duration customized

Boolean

ThresholdValue

Threshold values

Number

ThresholdDuration

Threshold Interval (Seconds)

Number

isAlertCustomized

Is alert customized

Boolean

isSendAlertToManager

Is alert notification to be sent to Manager configured

String

TimeStamp

Time stamp

String

Notification

Notification to be sent

Object

direction

Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH"

String

isAttackCustomized

Is DoS threshold attack customized

Boolean

Example

Request

GET https://<NSM_IP>/sdkapi/ipspolicy/0

Response

{
   "PolicyDescriptor":
   {
       "PolicyName": "IpsPolicy",
       "Description": "To test the IPS policy",
       "IsVisibleToChildren": true,
       "InboundRuleSet": "TestIPS",
       "OutboundRuleSet": "Null",
       "AttackCategory":
       {
           "ExpolitAttackList":
           [
               {
                   "attackName": "FTP: VMware Flaw in NAT Function",
                   "nspId": "0x4050b400",
                   "severity": 7,
                   "isSeverityCustomized": false,
                   "isEnabled": true,
                   "isAlertCustomized": false,
                   "isRecommendedForSmartBlocking": false,
                   "AttackResponse":
                   {
                       "TCPReset": "DISABLED",
                       "isTcpResetCustomized": false,
                       "isICMPSend": false,
                       "isICMPSendCustomized": false,
                       "mcAfeeNACNotification": "DISABLED",
                       "isMcAfeeNACNotificationEnabled": false,
                       "isQuarantineCustomized": false,
                       "isRemediateEnabled": false,
                       "blockingOption": "DISABLE",
                       "isBlockingOptionCustomized": false,
                       "isCapturedPrior": true,
                       "isCapturedPriorCustomized": false,
                       "action": "SEND_ALERT_ONLY",
                       "isLogCustomized": false,
                       "isFlowCustomized": false,
                       "isNbytesCustomized": false,
                       "numberOfBytesInEachPacket":
                       {
                           "LogEntirePacket":
                           {
                           }
                       }
                   },
                   "notification":
                   {
                       "isEmail": false,
                       "isPager": false,
                       "isScript": false,
                       "isAutoAck": false,
                       "isSnmp": false,
                       "isSyslog": false,
                       "isEmailCustomized": false,
                       "isPagerCustomized": false,
                       "isScriptCustomized": false,
                       "isAutoAckCustomized": false,
                       "isSnmpCustomized": false,
                       "isSyslogCustomized": false
                   },
                   "protocolList":
                   [
                       "ftp"
                   ],
                   "benignTriggerProbability": "1 (Low)",
                   "blockingType": "attack-packet",
                   "subCategory": "code-execution",
                   "direction": "INBOUND",
                   "isAttackCustomized": false
               }
           ]
       },
       "OutboundAttackCategory":
       {
       },
       "DosPolicy":
       {
           "LearningAttack":
           [
               {
                   "attackName": "TCP Control Segment Anomaly",
                   "nspId": "0x40008700",
                   "isSeverityCustomized": false,
                   "severity": 7,
                   "isBlockingSettingCustomized": false,
                   "isDropPacket": false,
                   "IsAlertCustomized": false,
                   "isSendAlertToManager": true,
                   "direction": "BOTH",
                   "notification":
                   {
                       "isEmail": false,
                       "isPager": false,
                       "isScript": false,
                       "isAutoAck": false,
                       "isSnmp": false,
                       "isSyslog": false,
                       "isEmailCustomized": false,
                       "isPagerCustomized": false,
                       "isScriptCustomized": false,
                       "isAutoAckCustomized": false,
                       "isSnmpCustomized": false,
                       "isSyslogCustomized": false
                   },
                   "isAttackCustomized": false
               }
           ],
           "ThresholdAttack":
           [
               {
                   "attackName": "Too Many Inbound TCP SYNs",
                   "nspId": "0x40008c00",
                   "isSeverityCustomized": false,
                   "severity": 6,
                   "isThresholdValueCustomized": false,
                   "isThresholdDurationCustomized": false,
                   "ThresholdValue": 2000,
                   "ThresholdDuration": 5,
                   "isAlertCustomized": false,
                   "isSendAlertToManager": false,
                   "Notification":
                   {
                       "isEmail": false,
                       "isPager": false,
                       "isScript": false,
                       "isAutoAck": false,
                       "isSnmp": false,
                       "isSyslog": false,
                       "isEmailCustomized": false,
                       "isPagerCustomized": false,
                       "isScriptCustomized": false,
                       "isAutoAckCustomized": false,
                       "isSnmpCustomized": false,
                       "isSyslogCustomized": false
                   },
                   "direction": "INBOUND",
                   "isAttackCustomized": false
               }
           ],
           "TimeStamp": "2012-06-20 18:44:55.000"
       },
       "DosResponseSensitivityLevel": 0,
       "IsEditable": false,
       "Timestamp": "2012-06-20 18:44:55.000",
       "VersionNum": 1,
       "IsLightWeightPolicy": false
   }
}

Error Information

Following error code is returned by this URL:

S.No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1108

Invalid policy Id