The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get the Ignore Rules

Prev Next

These URL's retrieves the details of the ignore rules.

Resource URL

GET /domain/<domainId>/attackfilter82?context = NTBA/SENSOR:

This URL is to retrieve all the details of all the ignore rules created within the given context and domain.

GET /domain/<domainId>/attackfilter82/<ruleId>?context = NTBA/SENSOR:

This URL is to get the details of the ignore rule created with the given rule Id within given context and domain.

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
domain_id Domain id Number Yes
ruleId Ignore rule id Number Yes (Only to get details of any specific ignore rule)

Query Parameters:

Field Name Description Data Type Mandatory
context Context of the ignore rule. Its values can be:
  • NTBA
  • SENSOR
String Yes (If not specified default is SENSOR)

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
attackFilter The details of the ignore rule created within the given domain Object

Details of attackFilter:

Field Name Description Data Type
id The unique identifier for an ignore rule Number
state Field to indicate whether an ignore rule is active or inactive. The values can be:
  • ENABLED
  • DISABLED
String
name Ignore rule name String
attack Attack details on which ignore rule is to be applied Object
resource Details of interface on which ignore rule should is to be applied Object
attacker Attacker details for ignore rule Object
target Target details for ignore rule Object
lastUpdatedByTime Last update time of an ignore rule Number
lastUpdatedByUserName The user by whom the ignore rule was last updated String
comment Comments for ignore rule String
ownerDomain The domain in which the ignore rule is created String

Details of attack:

Field Name Description Data Type
attackName Names of the attack String
attackDirection Direction of the attack. The values can be:
  • INBOUND
  • OUTBOUND
  • ANY
String

Details of resource:

Field Name Description Data Type
resourceId The ID of the interface/resource Number
resourceName Name of the interface String
resourceType Indicated the type of interface on which ignore rule is created. Its values can be:
  • 0: Resource type is domain (for domain level rules)
  • 1: Resource type is Sensor (for sensor level rules)
  • 2: Resource type is Vids (for interface and sub-interface level rules)
  • 3: Resource type is NTBA_ZONE (for rules defined for NTBA inside and outside zones)
  • 4: Resource type is NTBA_SENSOR (for rules at NTBA level)
  • 5: Resource type is NTBA_DOMAIN
Number
sensorId Id of the Sensor on which the rule is applicable Number

Details of attacker:

Field Name Description Data Type
AttackerEndPoint Attacker rule objects on which ignore rules will be applicable. String
AttackerPort Port type. Its value can be:
  • TCP
  • UDP
  • TCP_UDP
  • ANY
String
AttackerPortNumber
  • Port numbers
String

Details of target:

Field Name Description Data Type
TargetEndPoint Target rule objects on which ignore rules will be applicable String
TargetPort Port type. Its value can be:
  • TCP
  • UDP
  • TCP_UDP
  • ANY
String
TargetPortNumber
  • Port numbers
String

Example

Request

GET https://<NSM_IP>/sdkapi/domain/0/attackfilter82?context=SENSOR

Response

 {
	"id": 142,
  	"state": "ENABLED",
  	"name": "TEST IGNORE RULE_1",
 	"attack": 
{
    		"attackName":
 	[
     			 "0x45d20400"
   	 	],
   	 	"attackDirection": "INBOUND"
  	},
  	"resource":
 [
   		 {
      			"resourceID": 118,
      			"resourceName": "M-2950-1/1A-1B",
      			"resourceType": 2,
      			"sensorID": 1002
    		}
  	],
  	"attacker": 
{
    		"AttackerEndPoint":
 [
      			"0012_0040_0045_src",
      			"109_110_111_112_src"
    		 ],
    		"AttackerPort": "TCP",
    		"AttackerPortNumber": "25"
  	},
  	"target":
 {
    		"TargetEndPoint":
 [
      			"0012_0040_0045_src",
      			"118_117_116_116_dest"
    		 ],
    		"TargetPort": "TCP",
    		"TargetPortNumber": "25"
  	},
  	"lastUpdatedByTime": 1409726699000,
  	"lastUpdatedByUserName": "admin",
  	"comment": "Trellix IPS Manager",
  	"ownerDomain": "My Company"
} 
 

Example

Request

GET https://<NSM_IP>/sdkapi/domain/0/attackfilter82/142?context=SENSOR

Response

 {
	"id": 142,
  	"state": "ENABLED",
  	"name": "TEST IGNORE RULE_1",
 	"attack": 
{
    		"attackName":
 	[
     			 "0x45d20400"
   	 	],
   	 	"attackDirection": "INBOUND"
  	},
  	"resource":
 [
   		 {
      			"resourceID": 118,
      			"resourceName": "M-2950-1/1A-1B",
      			"resourceType": 2,
      			"sensorID": 1002
    		}
  	],
  	"attacker": 
{
    		"AttackerEndPoint":
 [
      			"0012_0040_0045_src",
      			"109_110_111_112_src"
    		],
    		"AttackerPort": "TCP",
    		"AttackerPortNumber": "25"
  	},
  	"target":
 {
    		"TargetEndPoint":
 [
      			"0012_0040_0045_src",
      			"118_117_116_116_dest"
    		],
    		"TargetPort": "TCP",
    		"TargetPortNumber": "25"
  	},
  	"lastUpdatedByTime": 1409726699000,
  	"lastUpdatedByUserName": "admin",
  	"comment": "Trellix IPS Manager",
  	"ownerDomain": "My Company"
} 
 

Error Information

Following error code is returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1408 Invalid rule id/provided rule id not visible to this domain