The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Rule throttling for performance and stability

Prev Next

Helix may disable a rule you created to ensure performance and stability. There are three circumstances that can result in your rule being throttled:

  1. Your rule matches on too many events per second. If you receive this error, you can:

    • Refine the rule’s query so that fewer events are likely to match.

  2. Your rule generated too many unique results. If you receive this error, you can:

    • Refine the rule’s query so that fewer events are likely to match.

    • Consider removing one field from the groupby parameter, if your rule uses more than one.

    • If the time window is greater than one minute, remove the window altogether.

  3. Your rule generated too many alerts within a window of time. This error is most often seen when a rule creates ten or more alerts in less than one second. If you receive this error, you can:

    • Refine the rule's query so that fewer events are likely to match.

    • Consider removing one field from the groupby parameter, if your rule uses more than one.