The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update the Firewall Logging

Prev Next

This URL updates the firewall logging for the Sensor.

Resource URL

PUT /sensor/<sensor_id>/firewalllogging

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

sensor_id

Sensor id

Number

Yes

Payload Parameters:

Field Name

Description

Data Type

Mandatory

isSuppressionEnabled

To enable the suppression

Boolean

Yes

individualMessage

Individual message

Number

Yes

suppressionInterval

Suppression interval

Number

Yes

uniqueSource

DestinationIPpairs

Unique source destination IP pairs

Number

Yes

loggingType

Logging type can be:

  • "DISABLE_DEVICE"

  • "LOG_ALL_MATCHED_TRAFFIC"

  • "LOG_ALL_DROPPED_DENIED_TRAFFIC"

  • "LOG_ALL_PERMITTED_TRAFFIC"

  • "LOG_MATCHED_TRAFFIC_ONLY"

String

Yes

deliveryType

Delivery type can be:

"MESSAGES_TO_TARGET_SYSLOGSERVER_VIA_MANAGER", "MESSAGES_TO_TARGET_SYSLOGSERVER_DIRECTLY_FROM_DEVICE"

String

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

status

Set to 1 if the operation was successful, -1 otherwise

Number

Example

Request

PUT https://<NSM_IP>/sdkapi/sensor/1001/firewalllogging

Payload

    {
  "loggingType": "LOG_ALL_MATCHED_TRAFFIC",
  "deliveryType": "MESSAGES_TO_TARGET_SYSLOGSERVER_VIA_MANAGER",
  "isSuppressionEnabled": false,
  "individualMessage": 25,
  "suppressionInterval": 120,
  "uniqueSourceDestinationIPpairs": 10
}

Response

{
"status": 1
}

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1106

Invalid Sensor

2

500

1124

The Sensor is inactive

3

400

6001

Sending messages directly to syslog server is not supported in I series Sensor

4

400

6002

Suppression interval should be between 1 and 3600

5

400

6003

Individual messages to send before suppressing should be between 1 and 25

6

400

6004

Unique source destination IP pair should be between 1 and 32