The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Cardinality condition

Prev Next

A cardinality condition counts unique field values. When the count is met, the rule triggers an alert. The following table describes the parameters you can use in a cardinality condition.

Name

Type

Required

Default

Description

items

List

Yes

Not applicable

A field, correlation, deviation, or cardinality.

groupby

String

No

Inherited from the parent

A comma-separated list of match expressions. It returns a string key to group items by. If it is specified, it overrides the groupby parameter defined in the parent item.

require

Number

Yes

Not applicable

Cardinality count at which trigger occurs. The value must be a positive integer.

cardinalityGroupby

String

Yes

Not applicable

A match expression used to group the cardinality.

caseSensitive

Boolean

No

True

Whether to treat the value of cadinalityGroupby key as case sensitive

In the following example, the rule looks for five successful log in attempts from the same IP address within a five minute period of time, and groups the results by IP address. The results are then grouped by username.

id: 1234567
version: 6789010
name:  O365 - Suspicious User login from Multiple IP Addresses
groupby: username
require: 1
within: 600s
items:
    - type: cardinality
      item:
        - type: fields
          match: class == "ms_office365" && action contains "userloggedin" && result == "success"
      require: 5
      cardinalityGroupby: srcipv4