The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Top Endpoint Executables

Prev Next

This URL retrieves the top endpoint executables.

Resource URL

GET /alerts/TopN/endpoint_executables

URL Parameters: None

Request Parameters

Payload Request Parameters: None

Query Parameters:

Field Name

Description

Data Type

Mandatory

duration

Indicates the start time for the alerts. The default value is LAST_14_DAYS. Duration can be:

  • LAST_5_MINUTES

  • LAST_1_HOUR

  • LAST_6_HOURS

  • LAST_12_HOURS

  • LAST_24_HOURS

  • LAST_48_HOURS

  • LAST_7_DAYS

  • LAST_14_DAYS

String

No

counttype

Allowed values are:

  • attackCount

  • endpointcount

Default value is endpointcount.

String

No

confidencetype

Confidence type can be:

  • malwareConfAny

  • malwareConfHigh

Default value is malwareConfHigh.

String

No

classificationtype

Allowed values are:

  • any

  • block

  • allow

  • unclassified

Default value is any.

String

No

Response Parameters

Following fields are returned.

Field Name

Description

Data Type

TopEndExecutablesList

List of the top endpoint executables

Array

Details of fields in TopEndpointExecutablesList:

Field Name

Description

Data Type

name

Executable name

String

fileHash

File hash

String

count

Endpoint count

Number

Example

Request

GET https://<NSM_IP>/sdkapi/alerts/TopN/endpoint_executables?duration=LAST_14_DAYS

Response

None

Response

    {
       "TopEndpointExecutablesList":[]
    }

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

500

1001

Internal error

2

400

3601

Invalid duration