The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get the Direct Syslog Configuration for the Domain

Prev Next

This URL retrieves the direct syslog configuration for the domain.

Resource URL

GET /domain/<domain_id>/directsyslog

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

domainId

Domain id

Number

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

enableSyslog

Enable logging

Boolean

isInherit

Inherit settings from parent resource

Boolean

serverIp

Syslog server IP

String

serverPort

Syslog server port (UDP)

Number

syslogFacility

Syslog facility

String

syslogPriorityMapping

Attack severity to syslog priority mapping

Object

message

Message format

String

filter

What attacks to log

Object

Details of syslogPriorityMapping:

Field Name

Description

Data Type

informationTo

Informational severity attack mapping

String

lowTo

Low severity attack mapping

String

mediumTO

Medium severity attack mapping

String

highTo

High severity attack mapping

String

Details of filter:

Field Name

Description

Data Type

LogSomeAttacks

Log some attacks

Object

LogAllAttacks

Log all attacks - empty object

Object

isQuarantineLogging

Log quarantined attacks

Boolean

Details of LogSomeAttacks:

Field Name

Description

Data Type

isExplicitlyEnabled

The attack definition has syslog notification explicitly enabled

Boolean

minimumSeverity

Minimum severity of attacks

Object

Details of minimumSeverity:

Field Name

Description

Data Type

isMinimumSeverity

Is minimum severity selected

Boolean

severityType

Type of the severity

String

Example

Request

GET https://<NSM_IP>/sdkapi/domain/0/directsyslog

Response

{
	'enableSyslog': 'true',
	'syslogPriorityMapping': {
		'lowTo': 'EMERGENCY_SYSTEM_UNUSABLE',
		'highTo': 'EMERGENCY_SYSTEM_UNUSABLE',
		'informationTo': 'EMERGENCY_SYSTEM_UNUSABLE',
		'mediumTO': 'EMERGENCY_SYSTEM_UNUSABLE'
	},
	'isInherit': 'false',
	'serverIp': '10.213.172.94',
	'filter': {
		'LogSomeAttacks': {
			'isExplicitlyEnabled': 'false',
			'minimumSeverity': {
				'isMinimumSeverity': 'false',
				'severityType': 'LOW'
			}
		}
	},
	'serverPort': '514',
	'syslogFacility': 'SECURITY_AUTHORIZATION_CODE_4',
	'message': 'Admin_Domain=$IV_ADMIN_DOMAIN$Alert_Type=$IV_ALERT_TYPE$Attack_Name=$IV_ATTACK_NAME$AttackConfidence=$IV_ATTACK_CONFIDENCE$DetectMech=$IV_DETECTION_MECHANISM$Category=$IV_CATEGORY$SubCategory=$IV_SUB_CATEGORY$INTF=$IV_INTERFACE$Attack_Id=$IV_ATTACK_ID$Attack_Count=$IV_ATTACK_COUNT$Attack_Severity=$IV_ATTACK_SEVERITY$Attack_Signature=$IV_ATTACK_SIGNATURE$Source_Ip=$IV_SOURCE_IP$Dest_Ip=$IV_DESTINATION_IP$Dest_Port=$IV_DESTINATION_PORT$Source_Port=$IV_SOURCE_PORT$Malware_Confidence=$IV_MALWARE_CONFIDENCE$Detection_Engine=$IV_MALWARE_DETECTION_ENGINE$Mal_File_Len=$IV_MALWARE_FILE_LENGTH$Mal_file_md5=$IV_MALWARE_FILE_MD5_HASH$Mal_File_Name=$IV_MALWARE_FILE_NAME$Mal_File_Type=$IV_MALWARE_FILE_TYPE$Mal_Vir_Name=$IV_MALWARE_VIRUS_NAME$Direction=$IV_DIRECTION$Nw_Protocol=$IV_NETWORK_PROTOCOL$AppProtocol=$IV_APPLICATION_PROTOCOL$Attack_Time=$IV_ATTACK_TIME$Qurantine_Time=$IV_QUARANTINE_END_TIME$Result_Status=$IV_RESULT_STATUS$Alert_UUID=$IV_SENSOR_ALERT_UUID$PeerName=$IV_SENSOR_CLUSTER_MEMBER$Sensor_Name=$IV_SENSOR_NAME$SourceOs=$IV_SOURCE_OS$DestOs=$IV_DEST_OS$Src_APN=$IV_SRC_APN$Dest_APN=$IV_DEST_APN$Src_IMSI=$IV_SRC_IMSI$Dest_IMSI=$IV_DEST_IMSI$Src_Phone=$IV_SRC_PHONE_NUMBER$Dest_Phone=$IV_DEST_PHONE_NUMBER$Vlan_ID=$IV_VLAN_ID$'
}

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1105

Invalid domain

2

400

6001

Direct sysog configuration is not present for this domain/Sensor