The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update Attack Filter

Prev Next

This URL updates an attack filter.

Resource URL

PUT /attackfilter/<attackfilter_id>

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
attackfilter_id Attack filter id Number Yes

Payload Parameters:

Field Name Description Data Type Mandatory
name Attack filter name String Yes
attackFilterId Attack filter id Number Yes
Description Description String No
DomainId Id of domain to which this attack filter belongs to Number Yes
LastModTs Last modified timestamp. For update, the LastModTs in PUT operation should be the same as returned by the GET operation for the same attack filter String Yes
Type Attack filter type, can be "IPV_4" / "IPV_6" / "TCP_UDP_PORT" / "IPV_4_TCP_UDP_PORT" / "IPV_6_TCP_UDP_PORT" String Yes
MatchCriteria Attack Filter Exclusion Object Yes

Details of MatchCriteria:

Field Name Description Data Type Mandatory
Exclusion List of IP - port exclusions Array Yes

Details of object in Exclusion (depends on the Type defined):

Field Name Description Data Type Mandatory
Ip IPv4 or IPv6 IP Object No
Port TCP / UDP port Object No

Details of Ip:

Field Name Description Data Type Mandatory
srcStart Source start IP String No
srcEnd Source end IP String No
destStart Destination start IP String No
destEnd Destination end IP String No
srcMode Source IP mode, can be "ANY_IP" / "ANY_EXTERNAL_IP" / "ANY_INTERNAL_IP" / "RANGE_IP" / "SINGLE_IP" String Yes
destMode Destination IP mode, can be "ANY_IP" / "ANY_EXTERNAL_IP" / "ANY_INTERNAL_IP" / "RANGE_IP" / "SINGLE_IP" String Yes

Details of port:

Field Name Description Data Type Mandatory
srcPort Source port String No
destPort Destination port String No
srcPortMode Source port mode, can be "ANY_PORT" / "TCP_OR_UDP" / "TCP" / "UDP" String Yes
destPortMode Destination port mode, can be "ANY_PORT" / "TCP_OR_UDP" / "TCP" / "UDP" String Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
status Status after update Number

Example

Request

PUT https://%3CNSM_IP%3E/sdkapi/attackfilter/419

Payload:
{
   "DomainId": 0, 
   "Description": "try", 
   "MatchCriteria": {
      "Exclusion": [
         {
            "Ip": {
               "destEnd": "1.1.1.17", 
               "destMode": "RANGE_IP", 
               "srcMode": "SINGLE_IP", 
               "srcStart": "1.1.1.1", 
               "destStart": "1.1.1.13", 
               "srcEnd": "1.1.1.11"
            }, 
            "Port": {
               "srcPortMode": "TCP", 
               "srcPort": "85", 
               "destPort": "89", 
               "destPortMode": "TCP"
            }
         }
      ]
   }, 
   "LastModTs": "2012-07-24 00:19:00", 
   "attackFilterId": 419, 
   "Type": "IPV_4_AND_TCP_UDP_PORT", 
   "name": "test1"
} 

Response

{
		"status":1
} 
 

Error Information

Following error codes are returned by this URL:

S.No HTTP Error Code SDK API errorId SDK API errorMessage
1 400 1001 Internal error
2 404 1105 Invalid domain
3 400 1409 Attack filter name should not be greater than 40 chars
4 400 1118 Please provide a name
5 400 1401 Unable to set attack filter type
6 400 1404 Please provide IP
7 400 1406 Invalid IP format
8 400 1407 Please provide port
9 400 1408 Invalid attack filter id
10 400 1414 Invalid source and destination combination
11 400 1415 Port not valid, please enter a number between 1 and 65535
12 400 1416 IP mode not valid
13 400 1418 Start IP should be less than end IP