The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Match expressions

Prev Next

Match expressions are Java-like expressions that examine the fields of an item and return a result. They are most commonly used in fields conditions, where they return a boolean result that indicates if the events fields match or not.

You can also use match expressions to produce the groupby value in a correlation rule. The groupby parameter is a comma-separated list of expressions, each of which can produce any type of result. If you use a match expression with the groupby parameter, the expression is normally a single field name, or a list of names. For example, the single field called username, or the comma-separated list of field names srcip, destip. However, match expressions can use any feature of the rule language. Each part of the groupby result is joined using a separator character, for example srcip, dstip could return a result of 10.0.0.1|10.0.0.2.

Finally, you can use match expressions in the output section of a rule to define the value of a field you want to add to a generated event. In this case, the expression can return any type of result.

The following table describes the types of values you can use in match expressions:

Parameter

Description

Format

string

A string

"string", or "escaped\x2estring", or 'single quote string', or `backtick string`

integer

A 64 bit signed integer number

1234, or 0xAbc

integer_range

A range of 64 bit signed integer numbers

None, see '->' range operator in Rule functions and operators

float

A double precision floating point number

3.14 or 1e10

float_range

A range of double precision floating point numbers

None, see '->' range operator in Rule functions and operators

boolean

A boolean

true or false

ip

A CIDR IP address range

10.0.0.1, or 10.0.0.0/8, or 1234::1, or 1234::1/128, or 1234::1.2.3.4

ip_range

A range of IP addresses

None, see '->' range operator in Rule functions and operators

regex

A regular expression (RE2 variant)

/[a-z]+/i