Skip to content

Intrusion Prevention

GET/settings/exclusions/intrusion-prevention

Endpoint API · Intrusion Prevention

Get all Intrusion Prevention exclusions.

Required permissionendpoint-state:read

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
page query integer No The page number to fetch, starting with 1.
pageSize query integer No The size of the page requested.
pageTotal query boolean No Whether the number of pages should be calculated and returned in the response.

Request samples

curl -X GET "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/intrusion-prevention" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"

import requests

response = requests.get(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/intrusion-prevention",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
    },
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/intrusion-prevention" -Headers $headers

package main

import (
    "fmt"
    "io"
    "net/http"
)

func main() {
    req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/intrusion-prevention", nil)
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/intrusion-prevention", {
  method: "GET",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
  },
});
const data = await response.json();
console.log(data);

Responses

200 — Page of Intrusion Prevention exclusions.

Response fields

itemsarray of objectrequired
List of Intrusion Prevention exclusions.
Intrusion Prevention exclusion.
Show child attributesHide child attributes
idstringrequired
Exclusion ID.
Must match the pattern [a-f0-9]{64}.
typestringrequired
Exclusion type. This is always intrusionPrevention.
Must be one of: intrusionPrevention.
localPortsarray of integer
Local allowed ports.
Each item must be ≥ 1 and ≤ 65535.
remotePortsarray of integer
Remote allowed ports.
Each item must be ≥ 1 and ≤ 65535.
directionstringrequired
Direction property of the intrusion prevention exclusion.
Must be one of: inbound, outbound, both.
remoteAddressesarray of string
Remote addresses to exempt from Intrusion Prevention checks.
commentstringrequired
Exclusion comment.
pagesobjectrequired
Show child attributesHide child attributes
currentintegerrequired
The 1-based page number being returned.
sizeintegerrequired
The size of the page being returned.
totalinteger
(Optional) The total number of pages that exist, if pageTotal=true in the request.
itemsinteger
(Optional) The total number of items across all pages.
maxSizeintegerrequired
The maximum page size that can be requested.

Errors

Status Meaning
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "items": [
    {
      "id": "string",
      "type": "intrusionPrevention",
      "localPorts": [
        0
      ],
      "remotePorts": [
        0
      ],
      "direction": "inbound",
      "remoteAddresses": [
        "string"
      ],
      "comment": "string"
    }
  ],
  "pages": {
    "current": 0,
    "size": 0,
    "total": 0,
    "items": 0,
    "maxSize": 0
  }
}

See the guide for a narrative walkthrough of this API.