The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update the Firewall Logging

Prev Next

This URL updates the firewall logging for the Sensor.

Resource URL

PUT /sensor/<sensor_id>/firewalllogging

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
sensor_id Sensor id Number Yes

Payload Parameters:

Field Name Description Data Type Mandatory
isSuppressionEnabled To enable the suppression Boolean Yes
individualMessage Individual message Number Yes
suppressionInterval Suppression interval Number Yes
uniqueSource

DestinationIPpairs

Unique source destination IP pairs Number Yes
loggingType Logging type can be:
  • "DISABLE_DEVICE"
  • "LOG_ALL_MATCHED_TRAFFIC"
  • "LOG_ALL_DROPPED_DENIED_TRAFFIC"
  • "LOG_ALL_PERMITTED_TRAFFIC"
  • "LOG_MATCHED_TRAFFIC_ONLY"
String Yes
deliveryType Delivery type can be:

"MESSAGES_TO_TARGET_SYSLOGSERVER_VIA_MANAGER", "MESSAGES_TO_TARGET_SYSLOGSERVER_DIRECTLY_FROM_DEVICE"

String Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
status Set to 1 if the operation was successful, -1 otherwise Number

Example

Request

PUT https://<NSM_IP>/sdkapi/sensor/1001/firewalllogging

Payload

 {
  "loggingType": "LOG_ALL_MATCHED_TRAFFIC",
  "deliveryType": "MESSAGES_TO_TARGET_SYSLOGSERVER_VIA_MANAGER",
  "isSuppressionEnabled": false,
  "individualMessage": 25,
  "suppressionInterval": 120,
  "uniqueSourceDestinationIPpairs": 10
} 

Response

{
"status": 1
} 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1106 Invalid Sensor
2 500 1124 The Sensor is inactive
3 400 6001 Sending messages directly to syslog server is not supported in I series Sensor
4 400 6002 Suppression interval should be between 1 and 3600
5 400 6003 Individual messages to send before suppressing should be between 1 and 25
6 400 6004 Unique source destination IP pair should be between 1 and 32