The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update Passive Device Profiling Setting at Sensor Level

Prev Next

This URL updates passive device profiling setting at the Sensor level.

Resource URL

PUT /sensor/<sensor_id>/passivedeviceprofiling

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

sensor_id

Domain id

Number

Yes

Payload Parameters:

Field Name

Description

Data Type

Mandatory

inheritSettingsfromParentNode

Inherit settings from parent node

Boolean

Yes

passiveDeviceProfilingSetting

Object that contains passive device profiling setting

Object

Yes

bindIPForCopiedDHCPTraffic

Bind monitoring port of a Sensor to receive a DHCP traffic with a relay agent

Boolean

Yes

bindIPAddressDetails

Object that contains monitoring port details for receiving DHCP traffic

Object

Yes

PassiveDeviceProfilingStateForSensor

Passive device profiling state on Sensor

String

Yes

interfaceStatusList

List of interfaces with enable status of passive device profiling setting in inbound/outbound direction

Object

Yes

Details of fields in passiveDeviceProfilingSetting:

Field Name

Description

Data Type

Mandatory

profilingTechniques

Profiling technique to use for device profiling

Object

Yes

profileExpiration

Profile expiration duration for re-profiling of a device

Object

Yes

hostInactivityTimerInHrs

Specifies the duration after which information for a device is considered invalid

Number

Yes

Details of fields in profilingTechniques:

Field Name

Description

Data Type

Mandatory

DHCPEnableStatus

Enable DHCP for device profiling

Boolean

Yes

TCPEnableStatus

Enable TCP for device profiling

Boolean

Yes

HTTPEnableStatus

Enable HTTP for device profiling

Boolean

Yes

Details of fields in profileExpiration:

Field Name

Description

Data Type

Mandatory

duration

Profile expiration duration

Number

Yes

unit

Profile expiration duration unit, can be "MINUTES" / "HOURS"

String

Yes

Details of fields in bindIPAddressDetails:

Field Name

Description

Data Type

Mandatory

designatedPort

Monitoring port of a Sensor to receive a DHCP traffic with a relay agent

String

Yes

portIPAddress

IP address of the monitoring port

String

Yes

networkMask

Network mask

String

Yes

defaultGateway

Default gateway

String

Yes

vlanID

VLAN id

String

Yes

Details of object in interfaceStatusList:

Field Name

Description

Data Type

Mandatory

interfaceId

Interface id

Number

Yes

interfaceName

Interface name

String

Yes

enableInbound

Enable status in inbound direction

Boolean

Yes

enableOutbound

Enable status in outbound direction

Boolean

Yes

subinterfaceStatusList

List of sub-interfaces in a particular interface with enable status of passive device profiling in inbound/outbound direction

Object

Yes

Details of fields in subinterfaceStatusList:

Field Name

Description

Data Type

Mandatory

interfaceId

Interface id

Number

Yes

interfaceName

Interface name

String

Yes

enableInbound

Enable status in inbound direction

Boolean

Yes

enableOutbound

Enable status in outbound direction

Boolean

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

status

Status returned by update

Number

Example

Request

PUT https://<NSM_IP>/sdkapi/sensor/1001/passivedeviceprofiling

Payload

{
       		"inheritSettingsfromIPSSettingsNode": true,
       		"passiveDeviceProfilingSetting":
       		{
           		"profilingTechniques":
           		{
               			"DHCPEnableStatus": false,
               			"TCPEnableStatus": false,
               			"HTTPEnableStatus": true
           		},
           		"profileExpiration":
           		{
               			"duration": 10,
               			"unit": "HOURS"
           		},
           		"hostInactivityTimerInHrs": 11
       		},
       		"bindIPForCopiedDHCPTraffic": true,
       		"bindIPAddressDetails":
       		{
           		"designatedPort": "4A",
           		"portIPAddress": "100.100.100.10",
           		"networkMask": "255.255.0.0",
           		"defaultGateway": "100.100.100.1",
           		"vlanID": "10"
       		},
"PassiveDeviceProfilingStateForSensor": "ENABLE_DEVICEPROFILING_FOR_ENTIRE_DEVICE",
       		"interfaceStatusList":
       		[
           		{
               			"interfaceId": 117,
               			"interfaceName": "3B",
               			"enableInbound": true,
               			"enableOutbound": true
           		},
           		{
               			"interfaceId": 105,
               			"interfaceName": "1A-1B",
               			"enableInbound": true,
               			"enableOutbound": true,
               			"subinterfaceStatusList":
               			[
                   				{
                       				"subInterfaceId": 118,
                       				"subInterfaceName": "TestVLAN1",
                       				"enableInbound": true,
                       				"enableOutbound": true
                   				}
               			]
           		},
           		{
               			"interfaceId": 104,
               			"interfaceName": "2A-2B",
               			"enableInbound": true,
               			"enableOutbound": true
           		},
           		{
               			"interfaceId": 103,
               			"interfaceName": "3A",
               			"enableInbound": true,
               			"enableOutbound": true
           		},
           		{
               			"interfaceId": 102,
               			"interfaceName": "4A-4B",
               			"enableInbound": true,
              			 "enableOutbound": true
           		}
       		]
    	}

Response

{
"status": 1
}

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1106

Invalid Sensor

2

400

3301

Profile expiration value must be between 5 and 59 minutes

3

400

3302

Profile expiration value must be between 1 and 12 hours

4

400

3303

Profile expiration value cannot be greater than host inactivity timer

5

400

3304

Please enable at least one profiling technique

6

400

3305

Inter connecting port cannot be specified as monitoring port

7

400

3306

Invalid monitoring port

8

400

3307

Invalid port IP address

9

400

3308

Invalid network mask

10

400

3309

Invalid default gateway

11

400

3310

VLAN id should be between 0 and 65535