The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Test the Direct Syslog Configuration for Domain

Prev Next

This URL tests the direct syslog configuration for the domain.

Resource URL

PUT /sensor/<sensor_id>/directsyslog

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
domainId Domain id Number Yes

Payload Request Parameters:

Field Name Description Data Type Mandatory
enableSyslog Enable logging Boolean Yes
isInherit Inherit settings from parent resource Boolean Yes
serverIp Syslog server IP String Yes
serverPort Syslog server port (UDP) Number Yes
syslogFacility Syslog Facility. Allowed values are:
  • SECURITY_AUTHORIZATION_CODE_10
  • SECURITY_AUTHORIZATION_CODE_4
  • LOG_AUDIT_NOTE_1
  • LOG_ALERT_NOTE_1
  • CLOCK_DAEMON_NOTE_2
  • LOCAL_USER_0
  • LOCAL_USER_1
  • LOCAL_USER_2
  • LOCAL_USER_3
  • LOCAL_USER_4
  • LOCAL_USER_5
  • LOCAL_USER_6
  • LOCAL_USER_7
String Yes
syslogPriorityMapping Attack severity to syslog priority mapping Object Yes
message Message format String Yes
filter What attacks to log Object Yes

Details of syslogPriorityMapping:

Field Name Description Data Type Mandatory
informationTo Informational severity attack mapping. Values allowed are:
  • EMERGENCY_SYSTEM_UNUSABLE
  • ALERT_ACTION_IMMEDIATELY
  • CRITICAL_CONDITIONS
  • ERROR
  • WARNING_CONDITIONS
  • NOTICE_NORAML_BUT_SIGNIFICANT_CONDITION
  • INFORMATIONAL_MESSGES
  • DEBUG_MESSAGES
String Yes
lowTo Low severity attack mapping. Values allowed are:
  • EMERGENCY_SYSTEM_UNUSABLE
  • ALERT_ACTION_IMMEDIATELY
  • CRITICAL_CONDITIONS
  • ERROR
  • WARNING_CONDITIONS
  • NOTICE_NORAML_BUT_SIGNIFICANT_CONDITION
  • INFORMATIONAL_MESSGES
  • DEBUG_MESSAGES
String Yes
mediumTO Medium severity attack mapping. Values allowed are:
  • EMERGENCY_SYSTEM_UNUSABLE
  • ALERT_ACTION_IMMEDIATELY
  • CRITICAL_CONDITIONS
  • ERROR
  • WARNING_CONDITIONS
  • NOTICE_NORAML_BUT_SIGNIFICANT_CONDITION
  • INFORMATIONAL_MESSGES
  • DEBUG_MESSAGES
String yes
highTo High severity attack mapping. Values allowed are:
  • EMERGENCY_SYSTEM_UNUSABLE
  • ALERT_ACTION_IMMEDIATELY
  • CRITICAL_CONDITIONS
  • ERROR
  • WARNING_CONDITIONS
  • NOTICE_NORAML_BUT_SIGNIFICANT_CONDITION
  • INFORMATIONAL_MESSGES
  • DEBUG_MESSAGES
String Yes

Details of filter:

Field Name Description Data Type Mandatory
LogSomeAttacks Log some attacks Object Yes
LogAllAttacks Log all attacks - empty object Object Yes
isQuarantineLogging Log quarantined attacks Boolean yes

Details of LogSomeAttacks:

Field Name Description Data Type Mandatory
isExplicitlyEnabled The attack definition has syslog notification explicitly enabled Boolean Yes
minimumSeverity Minimum severity of attacks Object Yes

Details of minimumSeverity:

Field Name Description Data Type Mandatory
isMinimumSeverity Is minimum severity selected Boolean Yes
severityType Type of the severity. Allowed values are:
  • INFORMATIONAL
  • LOW
  • MEDIUM
  • HIGH
String Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
status Set to 1 if the operation was successful Number

Example

Request

PUT https://<NSM_IP>/sdkapi/domain/0/directsyslog/testconnection

Payload

{
	'enableSyslog': 'true',
	'syslogPriorityMapping': {
		'lowTo': 'EMERGENCY_SYSTEM_UNUSABLE',
		'highTo': 'EMERGENCY_SYSTEM_UNUSABLE',
		'informationTo': 'EMERGENCY_SYSTEM_UNUSABLE',
		'mediumTO': 'EMERGENCY_SYSTEM_UNUSABLE'
	},
	'isInherit': 'false',
	'serverIp': '10.213.172.94',
	'filter': {
		'LogSomeAttacks': {
			'isExplicitlyEnabled': 'false',
			'minimumSeverity': {
				'isMinimumSeverity': 'false',
				'severityType': 'LOW'
			}
		}
	},
	'serverPort': '514',
	'syslogFacility': 'SECURITY_AUTHORIZATION_CODE_4',
	'message': 'Admin_Domain=$IV_ADMIN_DOMAIN$Alert_Type=$IV_ALERT_TYPE$Attack_Name=$IV_ATTACK_NAME$AttackConfidence=$IV_ATTACK_CONFIDENCE$DetectMech=$IV_DETECTION_MECHANISM$Category=$IV_CATEGORY$SubCategory=$IV_SUB_CATEGORY$INTF=$IV_INTERFACE$Attack_Id=$IV_ATTACK_ID$Attack_Count=$IV_ATTACK_COUNT$Attack_Severity=$IV_ATTACK_SEVERITY$Attack_Signature=$IV_ATTACK_SIGNATURE$Source_Ip=$IV_SOURCE_IP$Dest_Ip=$IV_DESTINATION_IP$Dest_Port=$IV_DESTINATION_PORT$Source_Port=$IV_SOURCE_PORT$Malware_Confidence=$IV_MALWARE_CONFIDENCE$Detection_Engine=$IV_MALWARE_DETECTION_ENGINE$Mal_File_Len=$IV_MALWARE_FILE_LENGTH$Mal_file_md5=$IV_MALWARE_FILE_MD5_HASH$Mal_File_Name=$IV_MALWARE_FILE_NAME$Mal_File_Type=$IV_MALWARE_FILE_TYPE$Mal_Vir_Name=$IV_MALWARE_VIRUS_NAME$Direction=$IV_DIRECTION$Nw_Protocol=$IV_NETWORK_PROTOCOL$AppProtocol=$IV_APPLICATION_PROTOCOL$Attack_Time=$IV_ATTACK_TIME$Qurantine_Time=$IV_QUARANTINE_END_TIME$Result_Status=$IV_RESULT_STATUS$Alert_UUID=$IV_SENSOR_ALERT_UUID$PeerName=$IV_SENSOR_CLUSTER_MEMBER$Sensor_Name=$IV_SENSOR_NAME$SourceOs=$IV_SOURCE_OS$DestOs=$IV_DEST_OS$Src_APN=$IV_SRC_APN$Dest_APN=$IV_DEST_APN$Src_IMSI=$IV_SRC_IMSI$Dest_IMSI=$IV_DEST_IMSI$Src_Phone=$IV_SRC_PHONE_NUMBER$Dest_Phone=$IV_DEST_PHONE_NUMBER$Vlan_ID=$IV_VLAN_ID$'
}

Response

{
"status": 1
}
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1105 Invalid domain
2 400 6002 IPV6 is not supported for direct syslog configuration
3 400 6002 Direct syslog is disabled or inherit settings has been selected