Skip to content

Intrusion Prevention

GET/settings/exclusions/intrusion-prevention/{exclusionId}

Endpoint API · Intrusion Prevention

Get an Intrusion Prevention exclusion by ID.

Required permissionendpoint-state:read

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
exclusionId path string (uuid) Yes Exclusion ID.

Request samples

curl -X GET "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/intrusion-prevention/<exclusionId>" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"

import requests

response = requests.get(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/intrusion-prevention/<exclusionId>",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
    },
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/intrusion-prevention/<exclusionId>" -Headers $headers

package main

import (
    "fmt"
    "io"
    "net/http"
)

func main() {
    req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/intrusion-prevention/<exclusionId>", nil)
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/intrusion-prevention/<exclusionId>", {
  method: "GET",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
  },
});
const data = await response.json();
console.log(data);

Responses

200 — Intrusion Prevention exclusion.

Response fields

idstringrequired
Exclusion ID.
Must match the pattern [a-f0-9]{64}.
typestringrequired
Exclusion type. This is always intrusionPrevention.
Must be one of: intrusionPrevention.
localPortsarray of integer
Local allowed ports.
Each item must be ≥ 1 and ≤ 65535.
remotePortsarray of integer
Remote allowed ports.
Each item must be ≥ 1 and ≤ 65535.
directionstringrequired
Direction property of the intrusion prevention exclusion.
Must be one of: inbound, outbound, both.
remoteAddressesarray of string
Remote addresses to exempt from Intrusion Prevention checks.
commentstringrequired
Exclusion comment.

Errors

Status Meaning
404 Can't find Intrusion Prevention exclusion.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "id": "string",
  "type": "intrusionPrevention",
  "localPorts": [
    0
  ],
  "remotePorts": [
    0
  ],
  "direction": "inbound",
  "remoteAddresses": [
    "string"
  ],
  "comment": "string"
}

See the guide for a narrative walkthrough of this API.