The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get the List of Active Botnets

Prev Next

This URL gets the list of active botnets in the domain.

Resource URL

GET /domain/<domain_id>/activebotnets?includeChildDomain=<includeChildDomain>&&duration=<duration>

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

domain_id

Domain id

Number

Yes

includeChildDomain

Should the child domains be included

Boolean

No

duration

Duration can be:

  • LAST_5_MINUTES

  • LAST_1_HOUR

  • LAST_6_HOUR

  • LAST_12_HOUR

  • LAST_24_HOUR

  • LAST_48_HOUR

  • LAST_7_DAYS

  • LAST_14_DAYS

String

No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

botnetDetailList

List of active botnets

ObjectList

Details of fields in botnetDetailList:

Field Name

Description

Data Type

name

Name of the active botnet

String

botId

If of the active botnet

Number

ccCommunication

C&C communication

String

events

Number of events

Number

lastEvent

Last event time

String

Example

Request

GET https://<NSM_IP>/sdkapi/domain/0/activebotnets

Response

    {
       "botnetDetailList":
       [
           {
               "name": "IRCBots",
               "botId": 6,
               "ccCommunication": "UN_BLOCKED",
               "events": 1,
               "lastEvent": "Jan 31 10:04 IST"
           }
       ]
    }

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1105

Invalid domain

2

404

4201

Invalid duration filter