The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get the Direct Syslog Configuration for the Sensor

Prev Next

This URL retrieves the direct syslog configuration for the Sensor.

Resource URL

GET /sensor/<sensor_id>/directsyslog

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
sensorId Sensor id Number Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
enableSyslog Enable logging Boolean
isInherit Inherit settings from parent resource Boolean
serverIp Syslog server IP String
serverPort Syslog server port (UDP) Number
syslogFacility Syslog facility String
syslogPriorityMapping Attack severity to syslog priority mapping Object
message Message format String
filter What attacks to log Object

Details of syslogPriorityMapping:

Field Name Description Data Type
informationTo Informational severity attack mapping String
lowTo Low severity attack mapping String
mediumTO Medium severity attack mapping String
highTo High severity attack mapping String

Details of filter:

Field Name Description Data Type
LogSomeAttacks Log some attacks Object
LogAllAttacks Log all attacks - empty object Object
isQuarantineLogging Log quarantined attacks Boolean

Details of LogSomeAttacks:

Field Name Description Data Type
isExplicitlyEnabled The attack definition has syslog notification explicitly enabled Boolean
minimumSeverity Minimum severity of attacks Object

Details of minimumSeverity:

Field Name Description Data Type
isMinimumSeverity Is minimum severity selected Boolean
severityType Type of the severity String

Example

Request

GET https://<NSM_IP>/sdkapi/sensor/1001/directsyslog

Response

{
	'enableSyslog': 'true',
	'syslogPriorityMapping': {
		'lowTo': 'EMERGENCY_SYSTEM_UNUSABLE',
		'highTo': 'EMERGENCY_SYSTEM_UNUSABLE',
		'informationTo': 'EMERGENCY_SYSTEM_UNUSABLE',
		'mediumTO': 'EMERGENCY_SYSTEM_UNUSABLE'
	},
	'isInherit': 'false',
	'serverIp': '10.213.172.94',
	'filter': {
		'LogSomeAttacks': {
			'isExplicitlyEnabled': 'false',
			'minimumSeverity': {
				'isMinimumSeverity': 'false',
				'severityType': 'LOW'
			}
		}
	},
	'serverPort': '514',
	'syslogFacility': 'SECURITY_AUTHORIZATION_CODE_4',
	'message': 'Admin_Domain=$IV_ADMIN_DOMAIN$Alert_Type=$IV_ALERT_TYPE$Attack_Name=$IV_ATTACK_NAME$AttackConfidence=$IV_ATTACK_CONFIDENCE$DetectMech=$IV_DETECTION_MECHANISM$Category=$IV_CATEGORY$SubCategory=$IV_SUB_CATEGORY$INTF=$IV_INTERFACE$Attack_Id=$IV_ATTACK_ID$Attack_Count=$IV_ATTACK_COUNT$Attack_Severity=$IV_ATTACK_SEVERITY$Attack_Signature=$IV_ATTACK_SIGNATURE$Source_Ip=$IV_SOURCE_IP$Dest_Ip=$IV_DESTINATION_IP$Dest_Port=$IV_DESTINATION_PORT$Source_Port=$IV_SOURCE_PORT$Malware_Confidence=$IV_MALWARE_CONFIDENCE$Detection_Engine=$IV_MALWARE_DETECTION_ENGINE$Mal_File_Len=$IV_MALWARE_FILE_LENGTH$Mal_file_md5=$IV_MALWARE_FILE_MD5_HASH$Mal_File_Name=$IV_MALWARE_FILE_NAME$Mal_File_Type=$IV_MALWARE_FILE_TYPE$Mal_Vir_Name=$IV_MALWARE_VIRUS_NAME$Direction=$IV_DIRECTION$Nw_Protocol=$IV_NETWORK_PROTOCOL$AppProtocol=$IV_APPLICATION_PROTOCOL$Attack_Time=$IV_ATTACK_TIME$Qurantine_Time=$IV_QUARANTINE_END_TIME$Result_Status=$IV_RESULT_STATUS$Alert_UUID=$IV_SENSOR_ALERT_UUID$PeerName=$IV_SENSOR_CLUSTER_MEMBER$Sensor_Name=$IV_SENSOR_NAME$SourceOs=$IV_SOURCE_OS$DestOs=$IV_DEST_OS$Src_APN=$IV_SRC_APN$Dest_APN=$IV_DEST_APN$Src_IMSI=$IV_SRC_IMSI$Dest_IMSI=$IV_DEST_IMSI$Src_Phone=$IV_SRC_PHONE_NUMBER$Dest_Phone=$IV_DEST_PHONE_NUMBER$Vlan_ID=$IV_VLAN_ID$'
}
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 400 1106 Invalid Sensor
2 404 1124 The Sensor is inactive
3 400 6001 Direct sysog configuration is not present for this domain/Sensor