The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Refine a date-based search using the Search bar

Prev Next

You can enter date and time taxonomy in the Search bar to refine the selected calendar range. The criteria in the Search bar take precedence over the criteria in the calendar. For example, the selected calendar range could be 30 Days. You can modify the query in the Search bar to use 20 days instead. The query range will take precedence over the calendar range. However, you cannot modify the query in the search bar to increase the time period selected in the calendar.

Note

The date and time you type in the search bar must be enclosed in single or double quotation marks (for example, eventtime>"2023-11-07T01:10"). However, if you use an option from a parsed field to add a date and time to the search, quotation marks are not needed. For details about using parsed field options, see Use event data to refine a search or run a new search.

Commonly searched timestamp fields include eventtime and meta_ts. The eventtime timestamp is created when a log event (such as a user opening a PDF file) occurs in your network. The meta_ts timestamp is created when a log ingestion device or service receives that log event from your environment and sends it to Helix. The meta_ts timestamp tracks the event through the Helix lifecycle. Both timestamps include the date and time to the millisecond.

The meta_ts timestamp is displayed in the first column of the search results table. This is the timestamp used to evaluate a search query and evaluate start and end expressions. Search results are displayed in meta_ts timestamp order by default.

The following example illustrates the relationship between timestamps in the calendar and in event details in search results. In this example, the custom date range for the search begins with April 7, 2022 at 12:58:37 p.m. and ends with April 8, 2022 at 23:59:59 p.m. The original search query was class=Trellix_nx, which returned all events of that class within the custom date range. To refine the search, eventtime=2022-04-08T15:24:50:001Z was added to the query.

Note

For details about the TQL syntax and additional examples, see the TQL Reference Guide.