The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update the Packet Capture Settings

Prev Next

This URL updates the packet capture settings.

Resource URL

PUT /sensor/<sensor_id>/packetcapture

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

sensor_id

Sensor id

Number

Yes

Payload Request Parameters:

Field Name

Description

Data Type

Mandatory

capTureSettings

Packet capture settings can be: monitoring SPAN port/manager/scp server

Object

No

templates

List of template names

StringList

No

rules

List of rules

ObjectList

No

Details of capTureSettings:

Field Name

Description

Data Type

Mandatory

monitoringSPANPort

Monitoring SPAN port details

Object

No

manager

Manager settings

Object

No

scpServer

SCP server settings

Object

No

Details of monitoringSPANPort:

Field Name

Description

Data Type

Mandatory

port

Monitoring SPAN port

String

No

captureDuration

Duration details

Object

Yes

Details of captureDuration:

Field Name

Description

Data Type

Mandatory

captureDurationInMinutes

Capture duration

Number

No

runTillExplicitlyReleased

Run until released

Boolean

Yes

Details of Manager:

Field Name

Description

Data Type

Mandatory

captureSizeinMB

Capture size

Number

Yes

Details of scp Server:

Field Name

Description

Data Type

Mandatory

scpServerIP

IP of SCP server

String

Yes

scpServerUserName

SCP user name

String

Yes

scpServerPassword

SCP server password

String

Yes

captureSizeinMB

Capture size

Number

Yes

Details of object in rules:

Field Name

Description

Data Type

Mandatory

ruleId

Rule id given if updating existing rule

Number

No

monitoringPort

Monitoring port. Give ALL if choosing for all ports

String

Yes

traffic

Traffic. Can be ALL/ARP/IP

String

Yes

protocol

Protocol. Can be TCP/UDP/ICMP/PROTOCOL_NUMBER

String

Yes

ipVersion

IP version. Can be IPV_4/IPV_6

String

Yes

fragmentsOnly

Fragments only

Boolean

Yes

sourceIP

Source IP

String

No

sourceMask

Source mask

Number

No

sourcePort

Source port

Number

No

destinationIP

Destination IP

String

No

destinationMask

Destination mask

Number

No

destinationPort

Destination port

Number

No

vlanId

VLAN id

Number

No

protocolNumber

Protocol number

Number

No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

status

Status returned

Number

Example

Request

PUT https://<NSM_IP>/sdkapi/sensor/1001/packetcapture

Payload

{
	"capTureSettings": {
		"monitoringSPANPort": {
			"port": "ALL",
			"captureDuration": {
				"captureDurationInMinutes": 0,
				"runTillExplicitlyReleased": true
			}
		},
		"manager": null,
		"scpServer": null
	},
	"templates": ["test",
	"test1"],
	"rules": [{
		"ruleId": 2,
		"monitoringPort": "ALL",
		"traffic": "ARP",
		"protocol": "TCP",
		"ipVersion": "IPV_4",
		"fragmentsOnly": true,
		"sourceIP": "0.0.0.0",
		"sourceMask": 0,
		"sourcePort": 0,
		"destinationIP": "0.0.0.0",
		"destinationMask": 0,
		"destinationPort": 0,
		"vlanId": 0,
		"protocolNumber": 0
	},
	{
		"ruleId": 3,
		"monitoringPort": "ALL",
		"traffic": "IP",
		"protocol": "ICMP",
		"ipVersion": "IPV_4",
		"fragmentsOnly": false,
		"sourceIP": "192.168.12.0",
		"sourceMask": 23,
		"sourcePort": 1,
		"destinationIP": "192.168.12.0",
		"destinationMask": 23,
		"destinationPort": 1,
		"vlanId": 1,
		"protocolNumber": 0
	},
	{
		"ruleId": null,
		"monitoringPort": "ALL",
		"traffic": "ALL",
		"protocol": "TCP",
		"ipVersion": "IPV_4",
		"fragmentsOnly": false,
		"sourceIP": "0.0.0.0",
		"sourceMask": 0,
		"sourcePort": 0,
		"destinationIP": "0.0.0.0",
		"destinationMask": 0,
		"destinationPort": 0,
		"vlanId": 0,
		"protocolNumber": 0
	}]
}

Response

{
"status": 1
}

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1106

Invalid Sensor

2

500

1124

The Sensor is inactive

3

400

6201

Packet capture not supported on this Sensor

4

400

6202

Packet capture duration should be between 1 and 9999

5

400

6203

Packet capture size should be between 1 and <maxsize>

6

400

6204

SCP server IP, username, password, and capture size are mandatory

7

400

6205

SCP server username should not contain space and special characters other than {-,_,.}

8

400

6206

File upload in progress so could not save the configuration now

9

400

6209

No template present for packet capturing --> <template_name>

10

400

6210

Protocol number should be between 1 and 65535 when PROTOCOL_NUMBER is selected as protocol while you have given --> <protocol_number>

11

400

6211

The rule id give to update is incorrect