The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get the Ignore Rules

Prev Next

These URL's retrieves the details of the ignore rules.

Resource URL

GET /domain/<domainId>/attackfilter82?context = NTBA/SENSOR:

This URL is to retrieve all the details of all the ignore rules created within the given context and domain.

GET /domain/<domainId>/attackfilter82/<ruleId>?context = NTBA/SENSOR:

This URL is to get the details of the ignore rule created with the given rule Id within given context and domain.

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

domain_id

Domain id

Number

Yes

ruleId

Ignore rule id

Number

Yes (Only to get details of any specific ignore rule)

Query Parameters:

Field Name

Description

Data Type

Mandatory

context

Context of the ignore rule. Its values can be:

  • NTBA

  • SENSOR

String

Yes (If not specified default is SENSOR)

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

attackFilter

The details of the ignore rule created within the given domain

Object

Details of attackFilter:

Field Name

Description

Data Type

id

The unique identifier for an ignore rule

Number

state

Field to indicate whether an ignore rule is active or inactive. The values can be:

  • ENABLED

  • DISABLED

String

name

Ignore rule name

String

attack

Attack details on which ignore rule is to be applied

Object

resource

Details of interface on which ignore rule should is to be applied

Object

attacker

Attacker details for ignore rule

Object

target

Target details for ignore rule

Object

lastUpdatedByTime

Last update time of an ignore rule

Number

lastUpdatedByUserName

The user by whom the ignore rule was last updated

String

comment

Comments for ignore rule

String

ownerDomain

The domain in which the ignore rule is created

String

Details of attack:

Field Name

Description

Data Type

attackName

Names of the attack

String

attackDirection

Direction of the attack. The values can be:

  • INBOUND

  • OUTBOUND

  • ANY

String

Details of resource:

Field Name

Description

Data Type

resourceId

The ID of the interface/resource

Number

resourceName

Name of the interface

String

resourceType

Indicated the type of interface on which ignore rule is created. Its values can be:

  • 0: Resource type is domain (for domain level rules)

  • 1: Resource type is Sensor (for sensor level rules)

  • 2: Resource type is Vids (for interface and sub-interface level rules)

  • 3: Resource type is NTBA_ZONE (for rules defined for NTBA inside and outside zones)

  • 4: Resource type is NTBA_SENSOR (for rules at NTBA level)

  • 5: Resource type is NTBA_DOMAIN

Number

sensorId

Id of the Sensor on which the rule is applicable

Number

Details of attacker:

Field Name

Description

Data Type

AttackerEndPoint

Attacker rule objects on which ignore rules will be applicable.

String

AttackerPort

Port type. Its value can be:

  • TCP

  • UDP

  • TCP_UDP

  • ANY

String

AttackerPortNumber

  • Port numbers

String

Details of target:

Field Name

Description

Data Type

TargetEndPoint

Target rule objects on which ignore rules will be applicable

String

TargetPort

Port type. Its value can be:

  • TCP

  • UDP

  • TCP_UDP

  • ANY

String

TargetPortNumber

  • Port numbers

String

Example

Request

GET https://<NSM_IP>/sdkapi/domain/0/attackfilter82?context=SENSOR

Response

{
    "rules": [
        {
            "id": 101,
            "state": "ENABLED",
            "name": "test",
            "attack": {
                "attackName": [
                    "0x40424800"
                ],
                "attackDirection": "ANY"
            },
            "resource": [
                {
                    "resourceID": 105,
                    "resourceName": "NS3100_1720/1-2",
                    "resourceType": 2,
                    "sensorID": 1001
                }
            ],
            "attacker": {
                "AttackerEndPoint": [
                    "The 172.16.0.0/12 network"
                ],
                "AttackerPort": "ANY",
                "AttackerPortNumber": ""
            },
            "target": {
                "TargetEndPoint": [
                    "The 192.168.0.0/16 network"
                ],
                "TargetPort": "ANY",
                "TargetPortNumber": ""
            },
            "targetHostName": [],
            "targetUrlCategories": [],
            "lastUpdatedByTime": 1674477194000,
            "lastUpdatedByUserName": "admin",
            "comment": "Test1",
            "ownerDomain": "My Company"
        }
    ]
}

Example

Request

GET https://<NSM_IP>/sdkapi/domain/0/attackfilter82/142?context=SENSOR

Response

    {
	"id": 142,
  	"state": "ENABLED",
  	"name": "TEST IGNORE RULE_1",
 	"attack": 
{
    		"attackName":
 	[
     			 "0x45d20400"
   	 	],
   	 	"attackDirection": "INBOUND"
  	},
  	"resource":
 [
   		 {
      			"resourceID": 118,
      			"resourceName": "NY-NS9500-1/G0/1-G0/2",
      			"resourceType": 2,
      			"sensorID": 1002
    		}
  	],
  	"attacker": 
{
    		"AttackerEndPoint":
 [
      			"0012_0040_0045_src",
      			"109_110_111_112_src"
    		],
    		"AttackerPort": "TCP",
    		"AttackerPortNumber": "25"
  	},
  	"target":
 {
    		"TargetEndPoint":
 [
      			"0012_0040_0045_src",
      			"118_117_116_116_dest"
    		],
    		"TargetPort": "TCP",
    		"TargetPortNumber": "25"
  	},
  	"lastUpdatedByTime": 1409726699000,
  	"lastUpdatedByUserName": "admin",
  	"comment": "Trellix IPS Manager",
  	"ownerDomain": "My Company"
}

Error Information

Following error code is returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1408

Invalid rule id/provided rule id not visible to this domain