The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Rule functions and operators

Prev Next

You can write any function that takes two parameters in both infix and prefix form. For example, you can use contains in prefix form like a function:

contains(filename, ".exe")

or you can use it in infix form like an operator:

filename contains ".exe"

The only functions or operators that have special treatment are the logical AND and OR. These can be written using Java-like && and ||, or as and and or. They can be used in infix form with two parameters:

srcip == 10.0.0.0/8 && dstip != 10.0.0.0/8
srcip == 10.0.0.0/8 and dstip != 10.0.0.0/8

Or they can be written in prefix form, where they can have as many parameters as desired.

or(srcip == 10.0.0.0/8, srcip == 172.16.0.0/12, srcip == 192.168.0.0/16)
||(srcip == 10.0.0.0/8, srcip == 172.16.0.0/12, srcip == 192.168.0.0/16)

You can also use list syntax for both AND and OR:

srcip == [10.0.0.0/8, 172.16.0.0.12, 192.168.0.0/16]
&[srcip, dstip] != 10.0.0.0/8

Lists can also be used on both sides of a comparison, where:

&[srcip, dstip] != &[10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16]

Is equivalent to:

(srcip != 10.0.0.0/8 && srcip != 172.16.0.0/12 && srcip != 192.168.0.0/16) && (dstip != 10.0.0.0/8 && dstip != 172.16.0.0/12 && dstip != 192.168.0.0/16)

Although these examples only include single constants in the lists, you can use any expression inside a list.

You can use the NOT operator, ! or not, to invert a boolean. For example:

!(srcip == 10.0.0.0/8 || srcip == 192.168.0.0/16)

In filter expressions, you can use the not operator with constants and with the list form of the AND or OR. If you use the not operator with a constant, the operator inverts the value of the constant. The following example checks if srcport has any value except for 80:

srcport == !80

Similarly, when used with a list, the not operator inverts the meaning. For example, the following will match any srcip within 10.0.0.0/8 except 10.0.0.1 and 10.0.0.2:

srcip == [10.0.0.0/8, ![10.0.0.1, 10.0.0.2]]
srcip == 10.0.0.0/8 && !(srcip == 10.0.0.1 || srcip == 10.0.0.2)

The following sections lists the types of functions you can use when you create or edit a rule.

Logical functions

The following table describes the supported logical functions.

Function

Name

Input parameter type

Output parameter type

Infix examples

Prefix examples

&&

And

boolean

boolean

true && true

&&(true, true, true, true)

||

Or

boolean

boolean

true || true

||(true, true, true, false)

!

Not

boolean

boolean

Not applicable

!true

Integer functions

The following table describes the supported integer functions.

Function

Name

Input parameter types

Output parameter type

Infix example

Prefix example

==

Equal to

integer and integer

boolean

1 == 2

==(1, 2)

==

Equal to

integer and integer_range

boolean

1 == 1 -> 10

==(1, 1 -> 10)

!=

Not equal to

integer and integer

boolean

1 != 2

!=(1, 2)

!=

Not equal to

integer and integer_range

boolean

1 != 10 -> 12

!=(1, 10 -> 12)

<

Less than

integer and integer

boolean

1 < 2

<(1, 2)

<=

Less than or equal to

integer and integer

boolean

1 <= 2

<=(1, 2)

>

Greater than

integer and integer

boolean

2 > 1

>(2, 1)

>=

Greater than or equal to

integer and integer

boolean

2 >= 1

>=(2, 1)

->

Range

integer and integer

integer_range

1 -> 100

->(1, 100)

+

Add

integer and integer

integer

1 + 1

+(1, 1)

-

Subtract

integer and integer

integer

1 - 1

-(1, 1)

*

Multiply

integer and integer

integer

1 * 2

*(1, 2)

/

Divide

integer and integer

integer

2 / 2

/(2, 2)

&

And

integer and integer

integer

0xff & 1

&(0xff, 1)

|

Or

integer and integer

integer

0xfe | 1

|(0xfe, 1)

^

Index

integer and integer

integer

0xff ^ 0xa5

^(0xff, 0xa5)

string

String

string

string

Not applicable

string(123)

Float functions

The following table describes the supported float functions.

Function

Name

Infix example

Prefix example

==

Equal to

1 == 2

==(1, 2)

==

Equal to

1 == 1 -> 10

==(1, 1 -> 10)

!=

Not equal to

1 != 2

!=(1, 2)

!=

Not equal to

1 != 10 -> 12

!=(1, 10 -> 12)

<

Less than

1 < 2

<(1, 2)

<=

Less than or equal to

1 <= 2

<=(1, 2)

>

Greater than

2 > 1

>(2, 1)

>=

Greater than or equal to

2 >= 1

>=(2, 1)

->

Range

1 -> 100

->(1, 100)

+

Add

1 + 1

+(1, 1)

-

Subtract

1 - 1

-(1, 1)

*

Multiply

1 * 2

*(1, 2)

/

Divide

2 / 2

/(2, 2)

&

And

0xff & 1

&(0xff, 1)

|

Or

0xfe | 1

|(0xfe, 1)

string

String

Not applicable

string(3.14)

String functions

The following table describes the supported string functions.

Function

Name

Infix example

Prefix example

==

Equal to

"abc" == "abc"

==("abc", "abc")

==

Equal to

"abc" == /[a-z]+/i

==("abc", /[a-z]+/i)

==

Equal to

/[a-z]+/i == "abc"

==(/[a-z]/i, "abc")

=~

Equal to. Not case sensitive.

"abc" == "ABC"

==("abc", "ABC")

!=

Not equal to

"abc" != "ABC"

!=("abc", "ABC")

!=

Not equal to

"abc" != /[0-9]+/

!=("abc", /[0-9]+/)

!=

Not equal to

/[0-9]+/ != "abc"

!=(/[0-9]+/, "abc")

!~

Not equal to. Not case sensitive.

"abc" != "123"

!=("abc", "123")

<

Less than

"abc" < "def"

<("abc", "def")

<=

Less than or equal to

"abc" <= "def"

<=("abc", "def")

>

Greater than

"abc" > "def"

>("abc", "def")

>=

Greater than or equal to

"abc" >= "def"

>=("abc", "def")

<~

Less than. Not case sensitive.

"abc" <~ "def"

<~("abc", "def")

<=~

Less than or equal to. Not case sensitive.

"abc" <=~ "def"

<=~("abc", "def")

>~

Greater than. Not case sensitive.

"abc" >~ "def"

>~("abc", "def")

>=~

Greater than or equal to. Not case sensitive.

"abc" >=~ "def"

>=~("abc", "def")

+

Add

"abc" + "def"

+("abc", "def")

capture

"a@b.com" capture "/[^@]+@(.*)/,1"

capture("a@b.com", /[^@]+@(.*)/, 1)

jsonpath

"{\"field\":\"value\"}" jsonpath "$.field"

jsonpath("{\"field\":\"value\"}", "$.field")

contains

"abc" contains "b"

contains("abc", "b")

containsNoCase

"abc" containsNoCase "B"

containsNoCase("abc", "B")

startsWith

"abc" startsWith "a"

startsWith("abc", "a")

startsWithNoCase

"abc" startsWithNoCase "A"

startsWithNoCase("abc", "A")

endsWith

"abc" endsWith "c"

endsWith("abc", "c")

endsWithNoCase

"abc" endsWithNoCase "C"

endsWithNoCase("abc", "C")

length

Not applicable

length("abc")

indexOf

"abc" indexOf "bc"

indexOf("abc", "bc")

indexOfNoCase

"abc" indexOfNoCase "BC"

indexOfNoCase("abc", "BC")

replace

Not applicable

replace("something", "some", "other")

substring

"abc" substring 1

substring("abc", 1)

substring

Not applicable

substring("abc", 1, 2)

strip

Not applicable

strip("   abc   ")

strip

"[{(abc)}]" strip "[]{}()"

strip("[{(abc)}]", "[]{}()")

distance

"abc" distance "xbc"

distance("abc", "xbc")

md5

Not applicable

md5("abcd")

md5

Not applicable

md5("abcd", "base64")

The second parameter is the output format, which can be either "hex" or "base64".

sha1

Not applicable

sha1("abcd")

sha1

Not applicable

sha256("abcd", "base64")

The second parameter is the output format, which can be either "hex" or "base64".

sha256

Not applicable

sha1("abcd")

sha256

Not applicable

sha256("abcd", "base64")

The second parameter is the output format, which can be either "hex" or "base64".

sha384

Not applicable

sha384("abcd")

sha384

Not applicable

sha384("abcd", "base64")

The second parameter is the output format, which can be either "hex" or "base64".

sha512

Not applicable

sha512("abcd")

sha512

Not applicable

sha512("abcd", "base64")

The second parameter is the output format, which can be either "hex" or "base64".

integer

Not applicable

integer("123")

float

Not applicable

float("3.14")

ip

Not applicable

ip("::1")

boolean

Not applicable

boolean("true")

IP address functions

The following table describes the supported IP address functions.

Function

Name

Infix example

Prefix example

==

Equal to

10.0.0.1 == ::1

==(10.0.0.1, ::1)

==

Equal to

10.0.0.1 == 10.0.0.1 -> 10.0.0.2

==(10.0.0.1, 10.0.0.1 -> 10.0.0.2)

!=

Not equal to

10.0.0.1 != ::1

!=(10.0.0.1, ::1)

!=

Not equal to

10.0.0.1 != 10.0.0.1 -> 10.0.0.2

!=(10.0.0.1, 10.0.0.1 -> 10.0.0.2)

->

Range

10.0.0.1 -> 10.0.0.3

->(10.0.0.1, 10.0.0.3)

first

Not applicable

first(10.0.0.0/8)

last

Not applicable

last(10.0.0.0/8)

string

Not applicable

string(::1)

integer

Not applicable

integer(10.0.0.1)

Aggregate functions

The following table describes the supported aggregate functions. All arguments used in each function must be of the same type.

Function

Input parameter types

Example

Description

count

boolean, datetime, integer, IP, float, and string

count(event_type == "account created") as numCreated

count(srcip, dstip) > 1

Takes one or more arguments and returns the number of those arguments with non-null values. If the arguments are boolean values, then they must also be true to be counted. If any of the arguments are arrays, then the individual array values are counted.

first

boolean, integer, IP, float, and string

first(username) as user

first(username, targetusername, callingusername)

Takes one or more arguments, scans them in order, and returns the first one with a non-null value. If any of the arguments are arrays, then the individual array values are tested, and a single item from the array is returned.

last

boolean, integer, IP, float, and string

last(username) as user

last(username, targetusername, callingusername)

Takes one or more arguments, scans them in order, and returns the last one with a non-null value. If any of the arguments are arrays, then the individual array values are tested, and a single item from the array is returned.

max

boolean, integer, IP, float, and string

max(size) as minSize

Takes one or more arguments, compares their values, and returns the one with the highest value. If one or more of the arguments are arrays, then each value in the array is compared.

min

boolean, integer, IP, float, and string

min(size) as minSize

Takes one or more arguments, compares their values, and returns the one with the lowest value. If one or more of the arguments are arrays, then each value in the array is compared.

sum

integer and float

Takes one or more arguments and sums all non-null values. If one or more arguments are arrays, then the individual array elements are summed.

Date functions

The following table describes the supported date functions.

Function

Name

Infix example

Prefix example

date

Date

Not applicable

date("2024-01-01")

==

Equal to

time_field == date("this week")

Not applicable

!=

Not equal to

time_field != date("today")

Not applicable

>

Less than

time_field > date("15 days ago")

Not applicable

>=

Less than or equal to

time_field >= date("last week")

Not applicable

<

Greater than

time_field < date("this year")

Not applicable

<=

Greater than or equal to

time_field <= date("last year")

Not applicable

The following table describes the supported date formats.

Date format

Description

yyyy-mm-dd

ISO date format without time that produces a time range covering the whole of the day described

yyyy-MM-ddTHH:mm:ss

yyyy-MM-dd HH:mm:ss

ISO date and time format that produces a time range covering the whole second described

now

The current time

today

A time range covering all of the current day from 00:00:00 to 23:59:59

yesterday

A time range covering all of yesterday

this hour

A time range covering all of the current hour

prev hour

A time range covering all of the previous hour

last hour

A time range spanning from (now - 1 hour) to now

this day

A time range covering all of today (equivalent to "today")

prev day

A time range covering all of yesterday (equivalent to "yesterday")

last day

A time range covering the previous 24 hours (from now-24h to now)

this week

A time range covering all of the current week

prev week

A time range covering all of the previous week

last week

A time range covering the previous 7 days

this month

A time range covering all of the current month

prev month

A time range covering all of the previous month

last month

A time range covering now-one month to now

this year

A time range covering the whole of the current year

prev year

A time range covering the whole of the previous year

last year

A time range from now-365 days to now

1 hour ago / X hours ago

Tests a time from an event against the specified age

1 day ago / X days ago

Tests a time from an event against the specified age

1 week ago / X weeks ago

Tests a time from an event against the specified age

1 month ago / X month ago

Tests a time from an event against the specified age

1 year ago / X years ago

Tests a time from an event against the specified age

Miscellaneous functions

The following table describes the supported miscellaneous functions.

Function

Infix example

Prefix example

has

Not applicable

has("fieldname")

Returns a value of true if fieldname exists

field

Not applicable

field("fieldname")

Returns the value of fieldname. This is required if the parameter name is the same as a function name.

field("fieldname", integer)

Returns the value of fieldname and converts it to an integer.

inWatchlist

"abc" inWatchlist "listname"

123 inWatchlist "listname"

10.0.0.1 inWatchlist "listname"

Checks if the value defined is in listname.

inWatchlist("abc", "listname")

inWatchlist("abc", "listname")

inWatchlist(10.0.0.1, "listname")

Checks if the value defined is in listname.