The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Has

Prev Next

The has function provides a filter for events that contain data in one or more fields.

The parameters to the has function are field names. Any number of field names can be specified. For example:

 has(dstcity)

Result: would return only results that included a populated dstcity field.

 has(dstcity,srccity)

Result: would return only results that included a populated dstcity field and a populated srccity field.

Note

The legacy has:field and has= field syntax is deprecated as of TQL 2.0.