Authentication

Prev Next

To use the NDR API, you need a valid user account on the NDR appliance with the UI/API role. You obtain a token that lasts for multiple consecutive requests.

Note

The user account with the UI/API role must be created on the NDR appliance before you can establish a session between the remote server and the NDR appliance. For more information about setting up user accounts on the NDR appliance, see the Network Detection and Response System Administration Guide.

By default, tokens expire after 24 hours. You can use the command-line interface (CLI) to change these defaults. For instructions on accessing the CLI, see the Network Detection and Response System Administration Guide or the Network Detection and Response User Guide.

Note

The examples in this document use tokens. If using port 443, you can also use basic authentication in place of tokens.

To check if your current session is still active, use the session request.

After you have finished using the NDR API, use the log out request.

Note

Trellix highly recommends that you log out of any session you open after you have finished.

The following authentication endpoints are available: