The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update an Ignore Rule

Prev Next

This URL updates an ignore rule.

Resource URL

POST /domain/<domainId>/attackfilter82/<ruleId>?context=SENSOR/NTBA

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

domain_id

Domain id

Number

Yes

ruleId

Rule id of the ignore rule to be updated

Number

Yes

Payload Request Parameters:

Field Name

Description

Data Type

Mandatory

attackFilter

The details of the ignore rules created within the given domain

Object

Yes

Details of attackFilter:

Field Name

Description

Data Type

Mandatory

id

The unique identifier for an ignore rule

Number

No

state

Field to indicate whether an ignore rule is active or inactive. The values can be:

  • ENABLED

  • DISABLED

String

Yes

name

Ignore rule name

String

Yes

attack

Attack details on which ignore rule is to be applied

Object

No

resource

Details of interface on which Ignore Rule should is to be applied

Object

No

attacker

Attacker details for ignore rule

Object

No

target

Target details for ignore rule

Object

No

lastUpdatedByTime

Time when an ignore rule was last updated

Number

No

lastUpdatedByUserName

The user by whom the ignore rule was last updated

String

No

comment

Comments for ignore rule

String

No

ownerDomain

The domain in which the ignore rule is created

String

No

Details of attack:

Field Name

Description

Data Type

Mandatory

attackName

Names of the attack

String

Yes

attackDirection

Direction of the attack. The values can be:

  • INBOUND

  • OUTBOUND

  • ANY

String

Yes

Details of resource:

Field Name

Description

Data Type

Mandatory

resourceId

The id of the interface/resource

Number

No

resourceName

Name of the interface

String

Yes (If not specified, default is MATCH ANY)

resourceType

Indicated the type of interface on which ignore rule is created. Its values can be:

  • 0: Resource type is domain (for domain level rules)

  • 1: Resource type is Sensor (for Sensor level rules)

  • 2: Resource type is Vids (for interface and sub-interface level rules)

  • 3: Resource type is NTBA_ZONE (for rules defined for NTBA inside and outside zones)

  • 4: Resource type is NTBA_SENSOR (for rules at NTBA level)

  • 5: Resource type is NTBA_DOMAIN

Number

No

sensorId

ID of the Sensor on which the rule is applicable

Number

No

Details of attacker:

Field Name

Description

Data Type

Mandatory

AttackerEndPoint

Attacker rule objects on which ignore rules will be applicable. The applicable rule object types for ignore rule are:

  • IPv4 address range

  • IPv4 endpoint

  • IPv4 network

  • IPv6 address range

  • IPv6 endpoint

  • IPv6 network

  • Network group for exception object

String

Yes (Default is Match ANY)

AttackerPort

Port type. Its value can be:

  • TCP

  • UDP

  • TCP_UDP

  • ANY

String

Yes (If not specified default is ANY)

AttackerPortNumber

  • Port numbers

String

Yes (not applicable for ANY port type)

Details of target:

Field Name

Description

Data Type

Mandatory

TargetEndPoint

Target rule objects on which ignore rules will be applicable. The applicable rule object types are:

  • IPv4 address range

  • IPv4 endpoint

  • IPv4 network

  • IPv6 address Range

  • IPv6 endpoint

  • IPv6 network

  • Network group for exception object

String

Yes (If not specified, default is MATCH ANY)

TargetPort

Port type. Its value can be:

  • TCP

  • UDP

  • TCP_UDP

  • ANY

String

Yes (If not specified, default is ANY port type)

TargetPortNumber

  • Port numbers

String

Yes (not applicable for ANY port type)

Note

One of the attacker and target request parameters must be specified.

Query Parameters:

Field Name

Description

Data Type

Mandatory

context

Context of the ignore rule. Its values can be:

  • NTBA

  • SENSOR

String

Yes (If not specified default is SENSOR)

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

status

Value 1 indicates resource is updated successfully

Number

Example

Request

PUT https://<NSM_IP>/sdkapi/domain/0/attackfilter82/143 ?context=SENSOR

Payload

{
       "state": "ENABLED",
       "name": "TEST IGNORE RULE_3",
       "attack":
       {
           "attackName":
           [
               ""
           ],
           "attackDirection": "INBOUND"
       },
       "resource":
       [
           {
               "resourceName": "NS3100_1720/1-2"
           }
       ],
       "attacker":
       {
           "AttackerEndPoint":
           [
               "0012_0040_0045_src",
               "109_110_111_112_src"
           ],
           "AttackerPort": "TCP",
           "AttackerPortNumber": "25"
       },
       "target":
       {
           "TargetEndPoint":
           [
               "0012_0040_0045_src",
               "118_117_116_116_dest"
           ],
           "TargetPort": "TCP",
           "TargetPortNumber": "25"
       },
       "comment": "Trellix IPS Manager",
    }  

Response

{
   "status": 1
}

In the above payload the Attack name from the TEST IGNORE RULE_3 has been removed.

After update the Response on getting details of TEST IGNORE RULE_3 is:

{
       "state": "ENABLED",
       "name": "TEST IGNORE RULE_3",
       "attack":
       {
           "attackName":
           [
               ""
           ],
           "attackDirection": "INBOUND"
       },
       "resource":
       [
           {
               "resourceName": "NS3100_1720/1-2"
           }
       ],
       "attacker":
       {
           "AttackerEndPoint":
           [
               "0012_0040_0045_src",
               "109_110_111_112_src"
           ],
           "AttackerPort": "TCP",
           "AttackerPortNumber": "25"
       },
       "target":
       {
           "TargetEndPoint":
           [
               "0012_0040_0045_src",
               "118_117_116_116_dest"
           ],
           "TargetPort": "TCP",
           "TargetPortNumber": "25"
       },
       "comment": "Trellix IPS Manager",
    }

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1408

Invalid rule id/provided rule id is not visible to this domain

2

400

1720

Invalid rule object/rule object is not visible in this domain

3

400

2513

Name must only letters, numerical, spaces, commas, periods, hyphen or underscore

4

400

1437

Rule name should not be longer than 64 characters

5

400

1433

This rule is invalid because it would match all alerts. Please specify at least one alert criterion

6

400

1434

Port number must be given for TCP, UDP, TCP_UDP port types.

7

400

1415

Port not valid, please enter a number between 1 and 65535

8

400

1422

Resource is not visible in this domain

9

400

1435

The same combination of IPv4 and IPv6 should be used in attacker and target endpoints.

10

400

1421

The attacker and target port fields are using an invalid protocol combination.

11

400

1436

One of the attacker or target criteria must be specified