The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Top Suspicious Flows

Prev Next

This URL retrieves the top suspicious flows for the given IP address.

Resource URL

GET /networkforensics/<ipaddress>/suspiciousflows ?startime=<start_time>&&duration=<duration>&&ntba=<ntba_id>

URL Parameters: ipaddress

Query Parameter1: starttime=

Date in the format yyyy-MM-dd HH:mm

Query Parameter 2: duration=

  • NEXT_60_SECONDS

  • NEXT_5_MINUTES

  • NEXT_60_MINUTES

  • NEXT_30_MINUTES

Query Parameter 3: ntba id

Request Parameters

Query Request Parameters:

Field Name

Description

Data Type

Mandatory

starttime

Start time for analysis

String

No

duration

Duration

String

No

Ntba_id

NTBA id

Number

No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

TopConversations

Top conversations

Object

Details of fields in TopConversations:

Field Name

Description

Data Type

time

Time

String

suspciousActivity

Suspicious activity

String

sourceEndpoint

Source host

String

sourcePort

Source port

Number

sourceEcecutable

Source executable name

String

destinationEndpoint

Destination endpoint

String

destinationPort

Destination port

Number

applications

Application names

String

attackName

Attack name

String

attackResult

Attack result

String

fileOrUrlAccessed

File or URL accessed

String

Example

Request

GET https://<NSM_IP>/sdkapi/networkforensics /1.1.1.1/ suspiciousflows?duration=NEXT_30_MINUTES&&starttime=2012-APR-20 12:15&ntba=1001

Response

    {
       "suspciousFlows":
       [
           {
               " time ": "10-Aug-2014 12:00",
               " suspciousActivity ": "",
               " sourceEcecutable ": "BitTorrent.exe",
               "executableClassification": "Allowed",
               "attackName": “”
           
       }  
     ]
    }

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

400

4301

Invalid duration

2

400

4302

Invalid time format

3

400

5000

Invalid IP address