The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Quarantine Host

Prev Next

This URL quarantines a Host for a particular duration on the specified Sensor.

Resource URL

POST /sensor/<sensor_id>/action/quarantinehost

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
sensor_id Sensor Id Number Yes

Payload Request Parameters:

Field Name Description Data Type Mandatory
IPAddress IPv4/IPv6 to be quarantined String Yes
Duration Duration for which the -IP is to be quarantined. Can be "FIFTEEN_MINUTES" / "THIRTY_MINUTES" / "FORTYFIVE_MINUTES" / "SIXTY_MINUTES" / "FOUR_HOURS" / "EIGHT_HOURS" / "UNTIL_EXPLICITLY_RELEASED" String Yes
remediate Remediate the IP along with quarantine Boolean No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
Status Status returned Number

Example

Request

POST https://<NSM_IP>/sdkapi/sensor/1001/action/quarantinehost

Payload:

{
   "IPAddress": "102.102.102.102", 
   "Duration": “EIGHT_HOURS”
   "remediate": true
} 

Response

{
"status":1
} 
 

Error Information

Following error codes are returned by this URL:

S.No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1106 Invalid Sensor
2 500 1124 The Sensor is inactive
3 400 1406 Invalid IP format
4 409 2301 IP already quarantined
5 400 2302 Invalid duration
6 400 2305 IPV6 is not enabled on Sensor