This URL is used to update the advanced device configuration at the Sensor level.
Resource URL
PUT /sensor/<sensorId>/ advanceddeviceconfiguration
Request Parameters
URL Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| sensorId | Sensor id | Number | Yes |
Payload Request Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| inheritSettings | Inherit settings from the parent domain | Boolean | Yes |
| preAttackBytestoCapture | Attack bytes to capture - Can be 128, 256 | Int | Yes |
| inspectTunneledTraffic | Inspect tunneled traffic | Boolean | Yes |
| cliActivityLogging | Log CLI activity. Values allowed are:
|
String | Yes |
| showCPUUsageinCLI | Show CPU usage in CLI | Boolean | Yes |
| restrictSSHAccesstoCLI | Restrict CLI access using SSH | Boolean | Yes |
| enableSSHLogging | Enable SSH logging | Boolean | Yes |
| permittedIPv4CIDRBlocks | The permitted IPv4 CIDR list for SSH access to CLI | Object | Yes |
| permittedIPv6CIDRBlocks | The permitted IPv6 CIDR list for SSH access to CLI | Object | Yes |
| useTraditionalSnort | Chooses either the traditional Trellix IPS Snort or the new Suricata Snort | Boolean | Yes |
Details of permittedIPv4CIDRBlocks:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| id | ID of the object | Int | No |
| cidr | IPv4 CIDR address | String | Yes |
| action | On delete action, the value should be 'delete' | String | Yes |
Details of permittedIPv6CIDRBlocks:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| id | ID of the object | Int | No |
| cidr | IPv6 CIDR address | String | Yes |
| action | On delete action, the value should be 'delete' | String | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| status | Set to 1 if the operation was successful | Number |
Example
Request
PUT https://<NSM_IP>/sdkapi/sensor/1001/advanceddeviceconfiguration
Payload
{
"inheritSettings": false,
"preAttackBytestoCapture": 128,
"inspectTunneledTraffic": false,
"cliActivityLogging": "DISABLED",
"showCPUUsageinCLI": false,
"restrictSSHAccesstoCLI": true,
"enableSSHLogging": false,
"permittedIPv4CIDRBlocks":
[
{
"id": 1,
"cidr": "1.1.1.1/32",
"action": null
}
],
"permittedIPv6CIDRBlocks":
[
{
"id": 2,
"cidr": "2001:0DB9:0000:0000:0000:0000:0000:0001/128",
"action": “delete”
}
] ,
“useTraditionalSnort”: true
}
Response
{
"status": 1
}
Error Information
Following error codes are returned by this URL:
| No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 404 | 1106 | Invalid Sensor |
| 2 | 400 | 1124 | The Sensor is inactive |
| 3 | 400 | 1001 | Pre attack packet capture bytes if provided, can only be 128 and 256 |
| 4 | 400 | 1701 | The cidrs provided are not present in the resource :: <list> |
| 5 | 400 | 1701 | The cidrs provided for addition are already present in the resource :: <list> |
| 6 | 400 | 1701 | Invalid CIDR notation : <list> |
| 7 | 400 | 1701 | Duplicate CIDR entry : <list> |
| 8 | 400 | 1001 | IP list is required |
| 9 | 500 | 1001 | Internal server errors |