Trellix Network Security

Download 50
Last updated Aug 2, 2023

trellix-nx-alerts

Fetch alerts from Trellix Network Security devices

trellix-nx-alerts [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss]
duration=NUM{mon|w|d|h|m|s}
Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example, 10s means data from 10 seconds earlier.
from=yyyyMMddHHmmss
Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=yyyyMMddHHmmss
End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero. Tomorrow 00:00 by default.

Output Fields

FieldTypeNameDescription
_timeDateTimeDetection time
profileStringProfileConnect profile name
ackBoolAckAcknowledged or not
typeStringType
inf_idIntegerInfection ID
file_typeStringFile type
signatureStringSignature
severityIntegerSeverity
src_ipIP addressSource IP
dst_ipIP addressDestination IP
urlStringURL
md5StringMD5
sha256StringSHA256
sc_versionStringSC VersionContent version
parentBoolParentParent alert or not
childBoolChildChild alert or not
uuidStringGUID
blocked_badgeBoolBlocked tag
threat_info_badgeBoolThreat info tag
ips_badgeBoolIPS tag
data_theft_badgeBoolData leak tag
erspan_badgeBoolERSPAN tag
icap_badgeBoolICAP tag
mtp_badgeBoolMTP tag
retroactive_badgeBoolRetroactive tag
vxlan_badgeBoolVXLAN tag