The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Classes

Prev Next

Classes in the Trellix Helix taxonomy represent types of events or log sources. For example:

  • A synthetic event created by an intel hit appears as class class:intel_hit.

  • An advisory generated by Trellix analytics appears as class:analytics.

A class is simply an identifier and can be any string. Trellix Helix uses a naming scheme of class=<vendor>_<product>. For example, class=palo_alto_http.

Note

Events that are not parsed or have not yet been seen in a Trellix Helix environment appear as class:unknown.