The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update an Ignore Rule

Prev Next

This URL updates an ignore rule.

Resource URL

POST /domain/<domainId>/attackfilter82/<ruleId>?context=SENSOR/NTBA

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
domain_id Domain id Number Yes
ruleId Rule id of the ignore rule to be updated Number Yes

Payload Request Parameters:

Field Name Description Data Type Mandatory
attackFilter The details of the ignore rules created within the given domain Object Yes

Details of attackFilter:

Field Name Description Data Type Mandatory
id The unique identifier for an ignore rule Number No
state Field to indicate whether an ignore rule is active or inactive. The values can be:
  • ENABLED
  • DISABLED
String Yes
name Ignore rule name String Yes
attack Attack details on which ignore rule is to be applied Object No
resource Details of interface on which Ignore Rule should is to be applied Object No
attacker Attacker details for ignore rule Object No
target Target details for ignore rule Object No
lastUpdatedByTime Time when an ignore rule was last updated Number No
lastUpdatedByUserName The user by whom the ignore rule was last updated String No
comment Comments for ignore rule String No
ownerDomain The domain in which the ignore rule is created String No

Details of attack:

Field Name Description Data Type Mandatory
attackName Names of the attack String Yes
attackDirection Direction of the attack. The values can be:
  • INBOUND
  • OUTBOUND
  • ANY
String Yes

Details of resource:

Field Name Description Data Type Mandatory
resourceId The id of the interface/resource Number No
resourceName Name of the interface String Yes (If not specified, default is MATCH ANY)
resourceType Indicated the type of interface on which ignore rule is created. Its values can be:
  • 0: Resource type is domain (for domain level rules)
  • 1: Resource type is Sensor (for Sensor level rules)
  • 2: Resource type is Vids (for interface and sub-interface level rules)
  • 3: Resource type is NTBA_ZONE (for rules defined for NTBA inside and outside zones)
  • 4: Resource type is NTBA_SENSOR (for rules at NTBA level)
  • 5: Resource type is NTBA_DOMAIN
Number No
sensorId ID of the Sensor on which the rule is applicable Number No

Details of attacker:

Field Name Description Data Type Mandatory
AttackerEndPoint Attacker rule objects on which ignore rules will be applicable. The applicable rule object types for ignore rule are:
  • IPv4 address range
  • IPv4 endpoint
  • IPv4 network
  • IPv6 address range
  • IPv6 endpoint
  • IPv6 network
  • Network group for exception object
String Yes (Default is Match ANY)
AttackerPort Port type. Its value can be:
  • TCP
  • UDP
  • TCP_UDP
  • ANY
String Yes (If not specified default is ANY)
AttackerPortNumber
  • Port numbers
String Yes (not applicable for ANY port type)

Details of target:

Field Name Description Data Type Mandatory
TargetEndPoint Target rule objects on which ignore rules will be applicable. The applicable rule object types are:
  • IPv4 address range
  • IPv4 endpoint
  • IPv4 network
  • IPv6 address Range
  • IPv6 endpoint
  • IPv6 network
  • Network group for exception object
String Yes (If not specified, default is MATCH ANY)
TargetPort Port type. Its value can be:
  • TCP
  • UDP
  • TCP_UDP
  • ANY
String Yes (If not specified, default is ANY port type)
TargetPortNumber
  • Port numbers
String Yes (not applicable for ANY port type)

Note

One of the attacker and target request parameters must be specified.

Query Parameters:

Field Name Description Data Type Mandatory
context Context of the ignore rule. Its values can be:
  • NTBA
  • SENSOR
String Yes (If not specified default is SENSOR)

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
status Value 1 indicates resource is updated successfully Number

Example

Request

PUT https://<NSM_IP>/sdkapi/domain/0/attackfilter82/143 ?context=SENSOR

Payload

{
       "state": "ENABLED",
       "name": "TEST IGNORE RULE_3",
       "attack":
       {
           "attackName":
           [
               ""
           ],
           "attackDirection": "INBOUND"
       },
       "resource":
       [
           {
               "resourceName": "M-2950-1/1A-1B"
           }
       ],
       "attacker":
       {
           "AttackerEndPoint":
           [
               "0012_0040_0045_src",
               "109_110_111_112_src"
           ],
           "AttackerPort": "TCP",
           "AttackerPortNumber": "25"
       },
       "target":
       {
           "TargetEndPoint":
           [
               "0012_0040_0045_src",
               "118_117_116_116_dest"
           ],
           "TargetPort": "TCP",
           "TargetPortNumber": "25"
       },
       "comment": "Trellix IPS Manager",
    } 

Response

{
   "status": 1
}

In the above payload the Attack name from the TEST IGNORE RULE_3 has been removed.

After update the Response on getting details of TEST IGNORE RULE_3 is:

{
       "state": "ENABLED",
       "name": "TEST IGNORE RULE_3",
       "attack":
       {
           "attackName":
           [
               ""
           ],
           "attackDirection": "INBOUND"
       },
       "resource":
       [
           {
               "resourceName": "M-2950-1/1A-1B"
           }
       ],
       "attacker":
       {
           "AttackerEndPoint":
           [
               "0012_0040_0045_src",
               "109_110_111_112_src"
           ],
           "AttackerPort": "TCP",
           "AttackerPortNumber": "25"
       },
       "target":
       {
           "TargetEndPoint":
           [
               "0012_0040_0045_src",
               "118_117_116_116_dest"
           ],
           "TargetPort": "TCP",
           "TargetPortNumber": "25"
       },
       "comment": "Trellix IPS Manager",
    } 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1408 Invalid rule id/provided rule id is not visible to this domain
2 400 1720 Invalid rule object/rule object is not visible in this domain
3 400 2513 Name must only letters, numerical, spaces, commas, periods, hyphen or underscore
4 400 1437 Rule name should not be longer than 64 characters
5 400 1433 This rule is invalid because it would match all alerts. Please specify at least one alert criterion
6 400 1434 Port number must be given for TCP, UDP, TCP_UDP port types.
7 400 1415 Port not valid, please enter a number between 1 and 65535
8 400 1422 Resource is not visible in this domain
9 400 1435 The same combination of IPv4 and IPv6 should be used in attacker and target endpoints.
10 400 1421 The attacker and target port fields are using an invalid protocol combination.
11 400 1436 One of the attacker or target criteria must be specified