The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Top Attackers

Prev Next

This URL retrieves the top attackers.

Resource URL

GET /alerts/TopN/attackers

Request Parameters

URL Parameters: None

Payload Request Parameters: None

Query Parameters:

Field Name Description Data Type Mandatory
duration Indicates the start time for the alerts. The default value is LAST_14_DAYS. Duration can be:
  • LAST_5_MINUTES
  • LAST_1_HOUR
  • LAST_6_HOURS
  • LAST_12_HOURS
  • LAST_24_HOURS
  • LAST_48_HOURS
  • LAST_7_DAYS
  • LAST_14_DAYS
String No

Response Parameters

Following fields are returned.

Field Name Description Data Type
TopAttackersList

List of top attackers

Array

Details of fields in TopAttackersList:

Field Name Description Data Type
attackerIP The attacker's IP address String
DNSName The DNS name String
attackCount Count of the attack Number

Example

Request

GET https://<NSM_IP>/sdkapi/alerts/TopN/attackers?duration=LAST_14_DAYS

Payload

None

Response

 {
						{"TopAttackersList":
						[{"attackerIP":"88.174.38.117","DNSName":"loy01-1-88-174-38-117.fbx.proxad.net.",
						"attackCount":35176},{"attackerIP":"172.16.230.71","DNSName":"---","attackCount":25852},	
						{"attackerIP":"1.1.1.9","DNSName":"---","attackCount":18876},
						{"attackerIP":"172.16.195.37","DNSName":"---","attackCount":18354},
						{"attackerIP":"133.35.136.9","DNSName":"nu-133-35-136-9.niigata-u.ac.jp.",
						"attackCount":14345},{"attackerIP":"192.168.1.92","DNSName":"---","attackCount":12860},
						{"attackerIP":"114.149.38.168","DNSName":"---","attackCount":11817},
						{"attackerIP":"133.35.72.14","DNSName":"nu-133-35-072.14.niigata-u.ac.jp.",
						"attackCount":11065},{"attackerIP":"2.2.88.8","DNSName":"---","attackCount":10337},
						{"attackerIP":"134.154.168.205","DNSName":"---","attackCount":10105}]}
		}
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 500 1001 Internal error
2 400 3601 Invalid duration