The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update the Packet Capture Settings

Prev Next

This URL updates the packet capture settings.

Resource URL

PUT /sensor/<sensor_id>/packetcapture

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
sensor_id Sensor id Number Yes

Payload Request Parameters:

Field Name Description Data Type Mandatory
capTureSettings Packet capture settings can be: monitoring SPAN port/manager/scp server Object No
templates List of template names StringList No
rules List of rules ObjectList No

Details of capTureSettings:

Field Name Description Data Type Mandatory
monitoringSPANPort Monitoring SPAN port details Object No
manager Manager settings Object No
scpServer SCP server settings Object No

Details of monitoringSPANPort:

Field Name Description Data Type Mandatory
port Monitoring SPAN port String No
captureDuration Duration details Object Yes

Details of captureDuration:

Field Name Description Data Type Mandatory
captureDurationInMinutes Capture duration Number No
runTillExplicitlyReleased Run until released Boolean Yes

Details of Manager:

Field Name Description Data Type Mandatory
captureSizeinMB Capture size Number Yes

Details of scp Server:

Field Name Description Data Type Mandatory
scpServerIP IP of SCP server String Yes
scpServerUserName SCP user name String Yes
scpServerPassword SCP server password String Yes
captureSizeinMB Capture size Number Yes

Details of object in rules:

Field Name Description Data Type Mandatory
ruleId Rule id given if updating existing rule Number No
monitoringPort Monitoring port. Give ALL if choosing for all ports String Yes
traffic Traffic. Can be ALL/ARP/IP String Yes
protocol Protocol. Can be TCP/UDP/ICMP/PROTOCOL_NUMBER String Yes
ipVersion IP version. Can be IPV_4/IPV_6 String Yes
fragmentsOnly Fragments only Boolean Yes
sourceIP Source IP String No
sourceMask Source mask Number No
sourcePort Source port Number No
destinationIP Destination IP String No
destinationMask Destination mask Number No
destinationPort Destination port Number No
vlanId VLAN id Number No
protocolNumber Protocol number Number No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
status Status returned Number

Example

Request

PUT https://<NSM_IP>/sdkapi/sensor/1001/packetcapture

Payload

{
	"capTureSettings": {
		"monitoringSPANPort": {
			"port": "ALL",
			"captureDuration": {
				"captureDurationInMinutes": 0,
				"runTillExplicitlyReleased": true
			}
		},
		"manager": null,
		"scpServer": null
	},
	"templates": ["test",
	"test1"],
	"rules": [{
		"ruleId": 2,
		"monitoringPort": "ALL",
		"traffic": "ARP",
		"protocol": "TCP",
		"ipVersion": "IPV_4",
		"fragmentsOnly": true,
		"sourceIP": "0.0.0.0",
		"sourceMask": 0,
		"sourcePort": 0,
		"destinationIP": "0.0.0.0",
		"destinationMask": 0,
		"destinationPort": 0,
		"vlanId": 0,
		"protocolNumber": 0
	},
	{
		"ruleId": 3,
		"monitoringPort": "ALL",
		"traffic": "IP",
		"protocol": "ICMP",
		"ipVersion": "IPV_4",
		"fragmentsOnly": false,
		"sourceIP": "192.168.12.0",
		"sourceMask": 23,
		"sourcePort": 1,
		"destinationIP": "192.168.12.0",
		"destinationMask": 23,
		"destinationPort": 1,
		"vlanId": 1,
		"protocolNumber": 0
	},
	{
		"ruleId": null,
		"monitoringPort": "ALL",
		"traffic": "ALL",
		"protocol": "TCP",
		"ipVersion": "IPV_4",
		"fragmentsOnly": false,
		"sourceIP": "0.0.0.0",
		"sourceMask": 0,
		"sourcePort": 0,
		"destinationIP": "0.0.0.0",
		"destinationMask": 0,
		"destinationPort": 0,
		"vlanId": 0,
		"protocolNumber": 0
	}]
} 

Response

{
"status": 1
} 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1106 Invalid Sensor
2 500 1124 The Sensor is inactive
3 400 6201 Packet capture not supported on this Sensor
4 400 6202 Packet capture duration should be between 1 and 9999
5 400 6203 Packet capture size should be between 1 and <maxsize>
6 400 6204 SCP server IP, username, password, and capture size are mandatory
7 400 6205 SCP server username should not contain space and special characters other than {-,_,.}
8 400 6206 File upload in progress so could not save the configuration now
9 400 6209 No template present for packet capturing --> <template_name>
10 400 6210 Protocol number should be between 1 and 65535 when PROTOCOL_NUMBER is selected as protocol while you have given --> <protocol_number>
11 400 6211 The rule id give to update is incorrect