Detect and Respond Traffic Detection Models
List of Requested Traffic Detection Models
Bad Request. Typically due to a malformatted JSON body, or parameter values are not validating.
Access token is missing or invalid
Access is forbidden
Unknown Error Occurred
Traffic Detection Model Create or Update Config
If true, portal and API will not display new events
falseIf true, alerts will not be processed by policies and integrations
falseCategories for the detection model
["system"]Detection model description
detection model descriptionDiscard lists are NQL statements that if matched do not get processed through the event. It enables skipping certain combinations without disabling the detection model
["bits > 10000"]If true, the detection model is enabled
trueFactors for the detection model
["srcip"]Name of the detection model
new_ndm_nameThe lookback period for the detection model. Min 15 seconds. Max 1 hour (3600)
300When ongoing updates should be sent. Max 6 hours (21600). 0 for disabled
0The context of record to be used for the detection model
flowPossible values: Requested Traffic Detection Model
Bad Request. Typically due to a malformatted JSON body, or parameter values are not validating.
Access token is missing or invalid
Access is forbidden
Unknown Error Occurred
The ID of the traffic detection model to be returned.
Requested Traffic Detection Model
Bad Request. Typically due to a malformatted JSON body, or parameter values are not validating.
Access token is missing or invalid
Access is forbidden
Unknown Error Occurred
The ID of the traffic detection model to be updated
Traffic Detection Model Create or Update Config
If true, portal and API will not display new events
falseIf true, alerts will not be processed by policies and integrations
falseCategories for the detection model
["system"]Detection model description
detection model descriptionDiscard lists are NQL statements that if matched do not get processed through the event. It enables skipping certain combinations without disabling the detection model
["bits > 10000"]If true, the detection model is enabled
trueFactors for the detection model
["srcip"]Name of the detection model
new_ndm_nameThe lookback period for the detection model. Min 15 seconds. Max 1 hour (3600)
300When ongoing updates should be sent. Max 6 hours (21600). 0 for disabled
0The context of record to be used for the detection model
flowPossible values: Requested Traffic Detection Model
Bad Request. Typically due to a malformatted JSON body, or parameter values are not validating.
Access token is missing or invalid
Access is forbidden
Unknown Error Occurred
The ID of the traffic detection model to be deleted
An empty array
Bad Request. Typically due to a malformatted JSON body, or parameter values are not validating.
Access token is missing or invalid
Access is forbidden
Unknown Error Occurred
No content
The ID of the traffic detection model to be enabled
Requested Traffic Detection Model
Bad Request. Typically due to a malformatted JSON body, or parameter values are not validating.
Access token is missing or invalid
Access is forbidden
Unknown Error Occurred
The ID of the traffic detection model to be disabled
Requested Traffic Detection Model
Bad Request. Typically due to a malformatted JSON body, or parameter values are not validating.
Access token is missing or invalid
Access is forbidden
Unknown Error Occurred
The ID of the traffic detection model to be reseted
Requested Traffic Detection Model
Bad Request. Typically due to a malformatted JSON body, or parameter values are not validating.
Access token is missing or invalid
Access is forbidden
Unknown Error Occurred
Last updated