The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Deviation condition

Prev Next

Deviation conditions look for changes to numeric values. For example, if you specify aggregate to be cardinality, this counts the number of unique values in a string, IP address, or other types of fields. This count is the numeric value that a deviation condition tests against. A deviation condition establishes an average baseline for the selected value and then looks for deviations from that baseline. To create the baseline, the condition creates a series of buckets that each cover a fixed period of time. The value from each event is then added to the appropriate bucket based on the timestamp of the event, and the average value and standard deviation for each bucket is calculated. When any one bucket deviates from the average of all buckets by the defined threshold, the condition triggers. You can select the number of buckets and the time period that each bucket covers. For example, 60 buckets each covering a 1 minute time period could detect the average of any one minute period deviating from the average for one hour either side of it.

The following table describes the parameters you can use in a deviation condition.

Name

Type

Required

Default

Description

items

List

Yes

Not applicable

A field, correlation, deviation, or cardinality.

groupby

String

No

Inherited from the parent

A comma-separated list of match expressions. It returns a string key to group items by. If it is specified, it overrides the groupby parameter defined in the parent item.

field

String

Yes

Not applicable

The name of the filed being counted.

aggregate

String

Yes

Not applicable

The type of aggregation to perform on the field: cardinality, sum, or average.

condition

String

Yes

False

A comparison expression comparing either stddev (standard deviation), percent, or count with a value. For example, stddev > 2.3.

bucketSize

Duration

No

1 minute

The period of time the bucket covers. The value must be a positive integer, followed by s (second), m (minute), or h (hour).

bucketCount

Number

No

1

The number of buckets. The value must be a positive integer.

In the following example, the rule looks for multiple host remote desktop log in attempts on the same user account. It creates five buckets each covering five minutes, and for each log in attempt looks for the parameters metaclass to equal windows, and eventid to equal 4624, and logontypeid to equal 10, and any field except username to end with $, and for there to be a field called hostname. Once the standard deviation of the hostname parameter varies by greater than five in any of the five buckets, the rule triggers. For each trigger of the rule, the results are grouped by username.

id: 12345678
version: 1676294234
name: Multiple Host RDP logins on same user account
groupby: username
require: 1
within: 600s
items:
    - type: deviation
      item:
        - type: fields
          match: > 
            metaclass == "windows" && eventid == "4624" && logontypeid == 10 && 
            (not username endsWith `$`) && has(hostname)
      field: hostname
      aggregate: cardinality
      condition: stddev > 5
      bucketSize: 5m
      bucketCount: 5