These URL's retrieves the details of the ignore rules.
Resource URL
GET /domain/<domainId>/attackfilter82?context = NTBA/SENSOR:
This URL is to retrieve all the details of all the ignore rules created within the given context and domain.
GET /domain/<domainId>/attackfilter82/<ruleId>?context = NTBA/SENSOR:
This URL is to get the details of the ignore rule created with the given rule Id within given context and domain.
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Domain id | Number | Yes |
| Ignore rule id | Number | Yes (Only to get details of any specific ignore rule) |
Query Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Context of the ignore rule. Its values can be:
| String | Yes (If not specified default is SENSOR) |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| The details of the ignore rule created within the given domain | Object |
Details of attackFilter:
Field Name | Description | Data Type |
|---|---|---|
| The unique identifier for an ignore rule | Number |
| Field to indicate whether an ignore rule is active or inactive. The values can be:
| String |
| Ignore rule name | String |
| Attack details on which ignore rule is to be applied | Object |
| Details of interface on which ignore rule should is to be applied | Object |
| Attacker details for ignore rule | Object |
| Target details for ignore rule | Object |
| Last update time of an ignore rule | Number |
| The user by whom the ignore rule was last updated | String |
| Comments for ignore rule | String |
| The domain in which the ignore rule is created | String |
Details of attack:
Field Name | Description | Data Type |
|---|---|---|
| Names of the attack | String |
| Direction of the attack. The values can be:
| String |
Details of resource:
Field Name | Description | Data Type |
|---|---|---|
| The ID of the interface/resource | Number |
| Name of the interface | String |
| Indicated the type of interface on which ignore rule is created. Its values can be:
| Number |
| Id of the Sensor on which the rule is applicable | Number |
Details of attacker:
Field Name | Description | Data Type |
|---|---|---|
| Attacker rule objects on which ignore rules will be applicable. | String |
| Port type. Its value can be:
| String |
|
| String |
Details of target:
Field Name | Description | Data Type |
|---|---|---|
| Target rule objects on which ignore rules will be applicable | String |
| Port type. Its value can be:
| String |
|
| String |
Example
Request
GET https://<NSM_IP>/sdkapi/domain/0/attackfilter82?context=SENSOR
Response
{
"rules": [
{
"id": 101,
"state": "ENABLED",
"name": "test",
"attack": {
"attackName": [
"0x40424800"
],
"attackDirection": "ANY"
},
"resource": [
{
"resourceID": 105,
"resourceName": "NS3100_1720/1-2",
"resourceType": 2,
"sensorID": 1001
}
],
"attacker": {
"AttackerEndPoint": [
"The 172.16.0.0/12 network"
],
"AttackerPort": "ANY",
"AttackerPortNumber": ""
},
"target": {
"TargetEndPoint": [
"The 192.168.0.0/16 network"
],
"TargetPort": "ANY",
"TargetPortNumber": ""
},
"targetHostName": [],
"targetUrlCategories": [],
"lastUpdatedByTime": 1674477194000,
"lastUpdatedByUserName": "admin",
"comment": "Test1",
"ownerDomain": "My Company"
}
]
}
Example
Request
GET https://<NSM_IP>/sdkapi/domain/0/attackfilter82/142?context=SENSOR
Response
{
"id": 142,
"state": "ENABLED",
"name": "TEST IGNORE RULE_1",
"attack":
{
"attackName":
[
"0x45d20400"
],
"attackDirection": "INBOUND"
},
"resource":
[
{
"resourceID": 118,
"resourceName": "NY-NS9500-1/G0/1-G0/2",
"resourceType": 2,
"sensorID": 1002
}
],
"attacker":
{
"AttackerEndPoint":
[
"0012_0040_0045_src",
"109_110_111_112_src"
],
"AttackerPort": "TCP",
"AttackerPortNumber": "25"
},
"target":
{
"TargetEndPoint":
[
"0012_0040_0045_src",
"118_117_116_116_dest"
],
"TargetPort": "TCP",
"TargetPortNumber": "25"
},
"lastUpdatedByTime": 1409726699000,
"lastUpdatedByUserName": "admin",
"comment": "Trellix IPS Manager",
"ownerDomain": "My Company"
}
Error Information
Following error code is returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 404 | 1408 | Invalid rule id/provided rule id not visible to this domain |