The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Top Endpoint Executables

Prev Next

This URL retrieves the top endpoint executables.

Resource URL

GET /alerts/TopN/endpoint_executables

Request Parameters

URL Parameters: None

Payload Request Parameters: None Query Parameters:
Field Name Description Data Type Mandatory
duration Indicates the start time for the alerts. The default value is LAST_14_DAYS. Duration can be:
  • LAST_5_MINUTES
  • LAST_1_HOUR
  • LAST_6_HOURS
  • LAST_12_HOURS
  • LAST_24_HOURS
  • LAST_48_HOURS
  • LAST_7_DAYS
  • LAST_14_DAYS
String No
counttype Allowed values are:
  • attackCount
  • endpointcount
Default value is endpointcount.
String No
confidencetype Confidence type can be:
  • malwareConfAny
  • malwareConfHigh

Default value is malwareConfHigh.

String No
classificationtype Allowed values are:
  • any
  • block
  • allow
  • unclassified

Default value is any.

String No

Response Parameters

Following fields are returned.

Field Name Description Data Type
TopEndExecutablesList List of the top endpoint executables Array

Details of fields in TopEndpointExecutablesList:

Field Name Description Data Type
name Executable name String
fileHash File hash String
count Endpoint count Number

Example

Request

GET https://<NSM_IP>/sdkapi/alerts/TopN/endpoint_executables?duration=LAST_14_DAYS

Response

None

Response

 {
       "TopEndpointExecutablesList":[]
    }
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 500 1001 Internal error
2 400 3601 Invalid duration