These URL's retrieves the details of the ignore rules.
Resource URL
GET /domain/<domainId>/attackfilter82?context = NTBA/SENSOR:
This URL is to retrieve all the details of all the ignore rules created within the given context and domain.
GET /domain/<domainId>/attackfilter82/<ruleId>?context = NTBA/SENSOR:
This URL is to get the details of the ignore rule created with the given rule Id within given context and domain.
Request Parameters
URL Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| domain_id | Domain id | Number | Yes |
| ruleId | Ignore rule id | Number | Yes (Only to get details of any specific ignore rule) |
Query Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| context | Context of the ignore rule. Its values can be:
|
String | Yes (If not specified default is SENSOR) |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| attackFilter | The details of the ignore rule created within the given domain | Object |
Details of attackFilter:
| Field Name | Description | Data Type |
|---|---|---|
| id | The unique identifier for an ignore rule | Number |
| state | Field to indicate whether an ignore rule is active or inactive. The values can be:
|
String |
| name | Ignore rule name | String |
| attack | Attack details on which ignore rule is to be applied | Object |
| resource | Details of interface on which ignore rule should is to be applied | Object |
| attacker | Attacker details for ignore rule | Object |
| target | Target details for ignore rule | Object |
| lastUpdatedByTime | Last update time of an ignore rule | Number |
| lastUpdatedByUserName | The user by whom the ignore rule was last updated | String |
| comment | Comments for ignore rule | String |
| ownerDomain | The domain in which the ignore rule is created | String |
Details of attack:
| Field Name | Description | Data Type |
|---|---|---|
| attackName | Names of the attack | String |
| attackDirection | Direction of the attack. The values can be:
|
String |
Details of resource:
| Field Name | Description | Data Type |
|---|---|---|
| resourceId | The ID of the interface/resource | Number |
| resourceName | Name of the interface | String |
| resourceType | Indicated the type of interface on which ignore rule is created. Its values can be:
|
Number |
| sensorId | Id of the Sensor on which the rule is applicable | Number |
Details of attacker:
| Field Name | Description | Data Type |
|---|---|---|
| AttackerEndPoint | Attacker rule objects on which ignore rules will be applicable. | String |
| AttackerPort | Port type. Its value can be:
|
String |
| AttackerPortNumber |
|
String |
Details of target:
| Field Name | Description | Data Type |
|---|---|---|
| TargetEndPoint | Target rule objects on which ignore rules will be applicable | String |
| TargetPort | Port type. Its value can be:
|
String |
| TargetPortNumber |
|
String |
Example
Request
GET https://<NSM_IP>/sdkapi/domain/0/attackfilter82?context=SENSOR
Response
{
"id": 142,
"state": "ENABLED",
"name": "TEST IGNORE RULE_1",
"attack":
{
"attackName":
[
"0x45d20400"
],
"attackDirection": "INBOUND"
},
"resource":
[
{
"resourceID": 118,
"resourceName": "M-2950-1/1A-1B",
"resourceType": 2,
"sensorID": 1002
}
],
"attacker":
{
"AttackerEndPoint":
[
"0012_0040_0045_src",
"109_110_111_112_src"
],
"AttackerPort": "TCP",
"AttackerPortNumber": "25"
},
"target":
{
"TargetEndPoint":
[
"0012_0040_0045_src",
"118_117_116_116_dest"
],
"TargetPort": "TCP",
"TargetPortNumber": "25"
},
"lastUpdatedByTime": 1409726699000,
"lastUpdatedByUserName": "admin",
"comment": "Trellix IPS Manager",
"ownerDomain": "My Company"
}
Example
Request
GET https://<NSM_IP>/sdkapi/domain/0/attackfilter82/142?context=SENSOR
Response
{
"id": 142,
"state": "ENABLED",
"name": "TEST IGNORE RULE_1",
"attack":
{
"attackName":
[
"0x45d20400"
],
"attackDirection": "INBOUND"
},
"resource":
[
{
"resourceID": 118,
"resourceName": "M-2950-1/1A-1B",
"resourceType": 2,
"sensorID": 1002
}
],
"attacker":
{
"AttackerEndPoint":
[
"0012_0040_0045_src",
"109_110_111_112_src"
],
"AttackerPort": "TCP",
"AttackerPortNumber": "25"
},
"target":
{
"TargetEndPoint":
[
"0012_0040_0045_src",
"118_117_116_116_dest"
],
"TargetPort": "TCP",
"TargetPortNumber": "25"
},
"lastUpdatedByTime": 1409726699000,
"lastUpdatedByUserName": "admin",
"comment": "Trellix IPS Manager",
"ownerDomain": "My Company"
}
Error Information
Following error code is returned by this URL:
| No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 404 | 1408 | Invalid rule id/provided rule id not visible to this domain |