The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Top Suspicious Flows

Prev Next

This URL retrieves the top suspicious flows for the given IP address.

Resource URL

GET /networkforensics/<ipaddress>/suspiciousflows ?startime=<start_time>&&duration=<duration>&&ntba=<ntba_id>

URL Parameters: ipaddress

Query Parameter1: starttime=

Date in the format yyyy-MM-dd HH:mm

Query Parameter 2: duration=

  • NEXT_60_SECONDS
  • NEXT_5_MINUTES
  • NEXT_60_MINUTES
  • NEXT_30_MINUTES

Query Parameter 3: ntba id

Request Parameters

Query Request Parameters:

Field Name Description Data Type Mandatory
starttime Start time for analysis String No
duration Duration String No
Ntba_id NTBA id Number No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
TopConversations Top conversations Object

Details of fields in TopConversations:

Field Name Description Data Type
time Time String
suspciousActivity Suspicious activity String
sourceEndpoint Source host String
sourcePort Source port Number
sourceEcecutable Source executable name String
destinationEndpoint Destination endpoint String
destinationPort Destination port Number
applications Application names String
attackName Attack name String
attackResult Attack result String
fileOrUrlAccessed File or URL accessed String

Example

Request

GET https://<NSM_IP>/sdkapi/networkforensics /1.1.1.1/ suspiciousflows?duration=NEXT_30_MINUTES&&starttime=2012-APR-20 12:15&ntba=1001

Response

 {
       "suspciousFlows":
       [
           {
               " time ": "10-Aug-2014 12:00",
               " suspciousActivity ": "",
               " sourceEcecutable ": "BitTorrent.exe",
               "executableClassification": "Allowed",
               "attackName": “”
           
       }  
     ]
    } 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 400 4301 Invalid duration
2 400 4302 Invalid time format
3 400 5000 Invalid IP address