The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Creating lists

Prev Next

No lists are populated in Helix until you create them. Use the following procedure to create a list.

Note

Newly created lists may take up to two minutes to appear in search results.

To create a list:

  1. From the main menu, select Configure > Lists.

  2. Click Create List on the Lists page.

    Helix_CreateNewList.png

  3. Enter a list name. Consider avoiding uppercase characters in the name. If you use the list name in a query, you must replace any uppercase characters with lowercase characters. See Understanding list attributes.Understanding list attributes

  4. (Optional) Add a description.

  5. Select Default, Analytics Allowed List, or Intel Matching as the list type.

  6. Slide the toggle to make the list Active or Inactive. Lists are Active by default.

  7. Click Create.

    Important

    Wildcards and aliases are not supported in lists. Each line is interpreted as an "or" Boolean operator in a query (that is, any search using the list will look for every item).

    If you intend to create a list of IP addresses and use that list against an IP address field (such as srcipv4 or dstipv4), then all of the items in the list need to be IP addresses. You cannot mix domain names and IP addresses in the same list or the search will fail.

  8. Add indicators to the list. See Adding indicators to a list.