The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update IPS Quarantine Duration for a Host

Prev Next

This URL will update the quarantine duration for the specified host.

Resource URL

PUT /sensor/<sensor_id>/action/quarantinehost

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

sensor_id

Sensor Id

Number

Yes

Payload Request Parameters:

Field Name

Description

Data Type

Mandatory

IPAddress

IPv4/IPv6 to be quarantined

String

Yes

Duration

Duration for which the quarantine needs to be extended for the specified IP, Can be "FIVE_MINUTES" / "FIFTEEN_MINUTES" / "THIRTY_MINUTES" / "FORTYFIVE_MINUTES" / "SIXTY_MINUTES" / "UNTIL_EXPLICITLY_RELEASED"

String

Yes

IsOverride

Override the previous data if present for the IP provided

Boolean

No

remediate

Remediate the IP along with quarantine. Considered only when override is selected.

Boolean

No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

Status

Status returned

Number

Example

Request

PUT https://<NSM_IP>/sdkapi/sensor/1001/action/quarantinehost

Payload

{
   "IPAddress": "102.102.102.102", 
   "Duration": “THIRTY_MINUTES”,
   “IsOverride”: true,
   “remediate”: true
}

Response

{
"status":1
}

Error Information

Following error codes are returned by this URL:

S.No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1106

Invalid Sensor

2

500

1124

The Sensor is inactive

3

400

1406

Invalid IP format

4

400

2302

Invalid duration

5

400

2303

IP not quarantined

6

400

2304

IP already quarantined for infinite duration

7

400

2305

IPV6 is not enabled on Sensor