Introduction

Prev Next

The Web Services Application Programming Interface (API) allows Trellix partners to access Trellix product alert records and reports and to submit malware objects and URLs for evaluation. The Web Services API is a role-based access control (RBAC) compliant Representational State Transfer (REST) interface.

The Web Services API supports both XML and JSON output. Furthermore, the Web Services API works on top of a unified alert access system, allowing any authenticated client to request alert records based on certain criteria.

During normal operations, the Central Management System appliance receives alerts and other data from the networked appliances. This data is held in the Central Management System database and is used to produce reports and alerts that are then available to the system users. Use the Web Services API to access and update these reports and alerts. You can also use the Web Services API to submit suspicious objects and URLs to the Malware Analysis appliance.

The commands in this reference are available on the following appliances:

NX

EX

FX

AX

CM

VX

Authentication

o

o

o

o

o

o

Alerts

o

o

o

o

o

Artifacts

o

o

o

o

o

Configuration

o

o

o

o

o

Email Quarantine

o

o

Feeds

o

YARA

o

o

o

o

o

o

SNORT

o

o

Submission

o

o

o

IPS Events

o

o

ATI

o

o

o

o

o

Reports

o

o

o

o

o

Statistics

o

o

Event filters

o

System Health

o