The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update the Advanced Device Configuration at Sensor Level

Prev Next

This URL is used to update the advanced device configuration at the Sensor level.

Resource URL

PUT /sensor/<sensorId>/ advanceddeviceconfiguration

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
sensorId Sensor id Number Yes

Payload Request Parameters:

Field Name Description Data Type Mandatory
inheritSettings Inherit settings from the parent domain Boolean Yes
preAttackBytestoCapture Attack bytes to capture - Can be 128, 256 Int Yes
inspectTunneledTraffic Inspect tunneled traffic Boolean Yes
cliActivityLogging Log CLI activity. Values allowed are:
  • DISABLED
  • DEVICE_ONLY
  • MANAGER_ONLY
  • DEVICE_AND_MANAGER
String Yes
showCPUUsageinCLI Show CPU usage in CLI Boolean Yes
restrictSSHAccesstoCLI Restrict CLI access using SSH Boolean Yes
enableSSHLogging Enable SSH logging Boolean Yes
permittedIPv4CIDRBlocks The permitted IPv4 CIDR list for SSH access to CLI Object Yes
permittedIPv6CIDRBlocks The permitted IPv6 CIDR list for SSH access to CLI Object Yes
useTraditionalSnort Chooses either the traditional Trellix IPS Snort or the new Suricata Snort Boolean Yes

Details of permittedIPv4CIDRBlocks:

Field Name Description Data Type Mandatory
id ID of the object Int No
cidr IPv4 CIDR address String Yes
action On delete action, the value should be 'delete' String Yes

Details of permittedIPv6CIDRBlocks:

Field Name Description Data Type Mandatory
id ID of the object Int No
cidr IPv6 CIDR address String Yes
action On delete action, the value should be 'delete' String Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
status Set to 1 if the operation was successful Number

Example

Request

PUT https://<NSM_IP>/sdkapi/sensor/1001/advanceddeviceconfiguration

Payload

{
        "inheritSettings": false,
        "preAttackBytestoCapture": 128,
        "inspectTunneledTraffic": false,
        "cliActivityLogging": "DISABLED",
        "showCPUUsageinCLI": false,
        "restrictSSHAccesstoCLI": true,
        "enableSSHLogging": false,
        "permittedIPv4CIDRBlocks":
        [
            {
                "id": 1,
                "cidr": "1.1.1.1/32",
                "action": null
            }
        ],
        "permittedIPv6CIDRBlocks":
        [
            {
                "id": 2,
                "cidr": "2001:0DB9:0000:0000:0000:0000:0000:0001/128",
                "action": “delete”
            }
        ] ,
        “useTraditionalSnort”: true
    } 

Response

{
"status": 1
} 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1106 Invalid Sensor
2 400 1124 The Sensor is inactive
3 400 1001 Pre attack packet capture bytes if provided, can only be 128 and 256
4 400 1701 The cidrs provided are not present in the resource :: <list>
5 400 1701 The cidrs provided for addition are already present in the resource :: <list>
6 400 1701 Invalid CIDR notation : <list>
7 400 1701 Duplicate CIDR entry : <list>
8 400 1001 IP list is required
9 500 1001 Internal server errors