The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Helix search

Prev Next

You aim to query the presence of events received and ingested into Helix. This is based on the native ability of Helix to search across events using its query language. The example illustrated here is aimed to obtain a total of events received over the last 24 hours, grouping them by type.

  1. On your Helix dashboard, click the magnification icon from the top right-hand side of the page. This expands the top of the page and displays few search fields.

  2. Set the following search criteria:

    1. Index Search (not Archive Search)

    2. The time window as Past 24 Hours

    3. The query text as has(class) class=fireeye_hx_ioc | groupby eventtype

  3. Submit the query by clicking the blue search button on the right edge of the query text field

Based on the data within your system, you should receive a response with some data. You can expand the time window to something that covers a wider scope of time if no hits have occurred in the last 24 hours in your Endpoint Security environment.

Helix_Search_1.jpg

From here you can further refine your search into areas of interest by clicking on any of the data fields that indicate a downward facing blue chevron image8.jpeg on the right edge of the field.