The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update the Alert Suppression

Prev Next

This URL updates the alert suppression for the Sensor.

Resource URL

PUT /sensor/<sensor_id>/ipsalerting/alertsuppression

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

sensor_id

Sensor id

Number

Yes

Payload Parameters:

Field Name

Description

Data Type

Mandatory

isEnabled

To enable the alert suppression

Boolean

Yes

uniqueSourceDestinationIPpairs

Source destination IP pairs

Number

Yes

individualAlerts

Individual alerts

Number

Yes

suppressSeconds

Suppress seconds

Number

Yes

alertCorrelation

Alert correlation

Number

Yes

packetsLoggedPerFlow

Packets logged

Number

Yes

enablePacketLogChannelEncryptio

Enable packet

Boolean

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

status

Set to 1 if the operation was successful, -1 otherwise

Number

Example

Request

PUT https://<NSM_IP>/sdkapi/sensor/1001/ipsalerting/alertsuppression

Payload

    {
  "isEnabled": true,
  "uniqueSourceDestinationIPpairs": 16,
  "individualAlerts": 2,
  "suppressSeconds": 2,
  "alertCorrelation": 3
		"packetsLoggedPerFlow": 6400,
		"enablePacketLogChannelEncryption": true
} 

Response

{
"status": 1
}

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1106

Invalid Sensor

2

500

1124

The Sensor is inactive

3

400

5701

Unique source destination IP pair should be between 1 and 32

4

400

5702

Individual alerts should be between 1 and 25

5

400

5703

Suppress seconds should be between 1 and 300

6

400

5704

Alert correlation should be between 1 and 10

7

400

5705

TCP 2MSL timer interval should be at least 3 seconds more than the alert correlation time