The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update Attack Filter

Prev Next

This URL updates an attack filter.

Resource URL

PUT /attackfilter/<attackfilter_id>

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

attackfilter_id

Attack filter id

Number

Yes

Payload Parameters:

Field Name

Description

Data Type

Mandatory

name

Attack filter name

String

Yes

attackFilterId

Attack filter id

Number

Yes

Description

Description

String

No

DomainId

Id of domain to which this attack filter belongs to

Number

Yes

LastModTs

Last modified timestamp. For update, the LastModTs in PUT operation should be the same as returned by the GET operation for the same attack filter

String

Yes

Type

Attack filter type, can be "IPV_4" / "IPV_6" / "TCP_UDP_PORT" / "IPV_4_TCP_UDP_PORT" / "IPV_6_TCP_UDP_PORT"

String

Yes

MatchCriteria

Attack Filter Exclusion

Object

Yes

Details of MatchCriteria:

Field Name

Description

Data Type

Mandatory

Exclusion

List of IP - port exclusions

Array

Yes

Details of object in Exclusion (depends on the Type defined):

Field Name

Description

Data Type

Mandatory

Ip

IPv4 or IPv6 IP

Object

No

Port

TCP / UDP port

Object

No

Details of Ip:

Field Name

Description

Data Type

Mandatory

srcStart

Source start IP

String

No

srcEnd

Source end IP

String

No

destStart

Destination start IP

String

No

destEnd

Destination end IP

String

No

srcMode

Source IP mode, can be "ANY_IP" / "ANY_EXTERNAL_IP" / "ANY_INTERNAL_IP" / "RANGE_IP" / "SINGLE_IP"

String

Yes

destMode

Destination IP mode, can be "ANY_IP" / "ANY_EXTERNAL_IP" / "ANY_INTERNAL_IP" / "RANGE_IP" / "SINGLE_IP"

String

Yes

Details of port:

Field Name

Description

Data Type

Mandatory

srcPort

Source port

String

No

destPort

Destination port

String

No

srcPortMode

Source port mode, can be "ANY_PORT" / "TCP_OR_UDP" / "TCP" / "UDP"

String

Yes

destPortMode

Destination port mode, can be "ANY_PORT" / "TCP_OR_UDP" / "TCP" / "UDP"

String

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

status

Status after update

Number

Example

Request

PUT https://<NSM_IP>/sdkapi/attackfilter/419

Payload:
{
   "DomainId": 0, 
   "Description": "try", 
   "MatchCriteria": {
      "Exclusion": [
         {
            "Ip": {
               "destEnd": "1.1.1.17", 
               "destMode": "RANGE_IP", 
               "srcMode": "SINGLE_IP", 
               "srcStart": "1.1.1.1", 
               "destStart": "1.1.1.13", 
               "srcEnd": "1.1.1.11"
            }, 
            "Port": {
               "srcPortMode": "TCP", 
               "srcPort": "85", 
               "destPort": "89", 
               "destPortMode": "TCP"
            }
         }
      ]
   }, 
   "LastModTs": "2012-07-24 00:19:00", 
   "attackFilterId": 419, 
   "Type": "IPV_4_AND_TCP_UDP_PORT", 
   "name": "test1"
}

Response

{
		"status":1
}

Error Information

Following error codes are returned by this URL:

S.No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

400

1001

Internal error

2

404

1105

Invalid domain

3

400

1409

Attack filter name should not be greater than 40 chars

4

400

1118

Please provide a name

5

400

1401

Unable to set attack filter type

6

400

1404

Please provide IP

7

400

1406

Invalid IP format

8

400

1407

Please provide port

9

400

1408

Invalid attack filter id

10

400

1414

Invalid source and destination combination

11

400

1415

Port not valid, please enter a number between 1 and 65535

12

400

1416

IP mode not valid

13

400

1418

Start IP should be less than end IP