The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Host sweep alert

Prev Next

All alerts that have iv_alert.alertType = 5 are hostsweep alerts. Its iv_alert_data.typeSpecific data has following format:

First byte contains number of IP information to follow. If there are ten IPs involved in the hostsweep, then first byte of typeSpecificData will contain value 10. Each subsequent four bytes will contain the actual IP values.

Total length of typeSpecificData in above example will be 1 + ( 10* 4) = 41 bytes.

The source and destination VLAN ID follow with each being 4 bytes. These fields are applicable only for NTBA alerts.

The details of the alert are as follows:

Number of bytes

Value

4

Connection rule ID

4

Connection drop count

1

External geographical location

1

External reputation

1

Connection rule type

4

Protocol ID

2

IP address count

4 (IPv4) or 16 (IPv6)

Version of the target IP address

1

Version information

4 (IPv4) or 16 (IPv6)

Proxy IP address

Variable length

Packet logs

Host sweep alert
Host sweep alert