The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Field condition

Prev Next

A field condition uses an expression to match an event. For example, you might want to match to an event type like a login failure, or a source or destination IP address. For a list of the expressions you can use, see Match expressions.

The following table describes the parameters you can use in a field match condition.

Name

Type

Required

Default

Description

match

String

Yes

Not applicable

This is a field match expression that returns a true or false value.

type

String

Yes

Not applicable

You must use the parameter fields.

groupby

String

No

Inherited from the parent

A comma-separated list of match expressions. It returns a string key to group items by. If it is specified, it overrides the groupby parameter defined in the parent item.

In the following example, the rule looks for events where the value of xpod_ds_name is helix. If the rule sees 100 matches within a one hour period of time, it triggers an alert.

id: 123
version: 123456789
name: Trigger on 100 events
require: 1
threshold: 100
within: 1h
items:        
    - type: fields
      match: xpod_ds_name == "helix"