The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Host sweep alert

Prev Next

All alerts that have iv_alert.alertType = 21 are NTBA host sweep alerts. Its iv_alert_data.typeSpecific data has the following format:

First byte contains number of the IP information to follow. If there are ten IPs involved in the hostsweep, then the first byte of typeSpecificData will have a value of 10. Every subsequent four bytes will contain the actual IP values.

Total length of typeSpecificData in the above example will be 1 + ( 10* 4) + 8 = 49 bytes.

The details of the alert are as follows:

Number of bytes Value
4 Connection rule ID
4 Connection drop count
1 External geographical location
1 External reputation
1 Connection rule type
4 Protocol ID
2 IP address count
4 (IPv4) or 16 (IPv6) Version of the target IP address
1 Version information
4 (IPv4) or 16 (IPv6) Proxy IP address
Variable length Packet log
NTBA host sweep alert