The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update All Alerts

Prev Next

This URL is used to retrieve all alerts.

Resource URL

UPDATE /alerts? alertstate=<state> &timeperiod==<timeperiod> &startime==<start_time> &endtime=<end_time>& search=<search_strng>&filter=<filter_value>

Request Parameters

Query Parameters:

Field Name Description Data Type Mandatory
alertstate Alert state, values allowed are, ANY/Acknowledged/Unacknowledged String No
timeperiod Time period, allowed values are
  • LAST_5_MINUTES
  • Last_1_HOUR
  • LAST_6_HOURS
  • LAST_12_HOURS
  • LAST_24_HOURS
  • LAST_7_DAYS
  • LAST_14_DAYS
  • CUSTOM
String No
starttime Start time String No
endtime End time String No
search Search String No
Filter Filter on following column is allowed

name, assignTo, application, layer7Data, result, attackCount, relevance, alertId, direction, device, domain, interface, attackSeverity, nspId, btp, attackCategory, malwarefileName, malwarefileHash, malwareName, malwareConfidence, malwareEngine ,executableName, executableHash, executableConfidenceName, attackerIPAddress, attackerPort, attackerRisk, attackerProxyIP, attackerHostname, targetIPAddress, targetPort, targetRisk, targetProxyIP, targetHostname, botnetFamily

Ex: name:Malware;direction:Inbound,Outbound;attackcount:>3,<4

String No

Payload parameters:

Field Name Description Data Type
alertState Alert state String
assignTo User id String

Response Parameters

Following fields are returned.

Field Name Description Data Type
status Set to 1 if the operation was successful, -1 otherwise Number

Example

Request

UPDATE https://<NSM_IP>/sdkapi/alerts?fromalert=1334242&page=next&timeperiod=custom&starttime=10/10/2015 12:00&endtime=01/12/2015 12:00

{
	"alertState": "Acknowledged",
           "assignTo": "admin"
}

Response

{
"status":1
           } 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 3704 Invalid filter value
2 404 9803 Sensor id is required
3 404 9803 Manager name is required