The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Customize the search results table

Prev Next

Search results are displayed in a table, which makes it easier to scan data and quickly recognize patterns. Each row represents an event that matched the search criteria. Each column represents a field in that event.

Events typically have too many fields to fit as columns in the table. You can specify which columns to include or exclude and change the order in which they are displayed. Instead of scrolling through a long list of fields, you can start typing the name of the field you want to show or hide in the Search box.

Tip

Turn on the Parsed or Raw toggles to only see that data in the search results table. If one or both toggles are on, all other columns except the meta_ts colum are hidden. Turn off both toggles to revert to the previous column set.

To customize the search results table:

  1. Run or rerun a search.

  2. Click the icon in the right-most column header on the search results table. Then select Customize Columns. The Columns dialog opens.

    The fields from the event are listed, those that are currently included in columns and those that are currently hidden.

  3. To show or hide a column, select or clear the checkbox next to the field name.

  4. To define the order of columns, drag the icon to the left of the checkbox up or down the list.

  5. If you are satisfied with the table, do one of the following:

    1. To save the new table layout, click Save.

    2. To create a custom column set, click Save As, enter a name for the column set, and then click Save As. You can now select the new column set from the menu above the search results table.

    Note

    You cannot edit the columns in a Trellix column set.

  6. To restore the table to the default column order, click Reset.