The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Search best practices

Prev Next

  • Use a list and refer to it instead of repeatedly using arrays.

  • Regular expression (regex) operations can be performed against a maximum of 50,000 events for each search in Helix. To perform regex operations against larger datasets, you must filter search results to fewer than 50,000 events. Otherwise, the search will not complete successfully.

  • Encapsulate all string patterns with single or double quotation marks to help ensure that Helix accurately interprets the string. For example:

    • Using spaces and special characters within a rawmsg string pattern can result in inconsistent search results. To avoid this, either encapsulate single words with quotation marks as noted above or use the AND operator between words. For example:

    • count>"4"

    • eventtime>'2022-04-07T01:10:50:000Z'

  • Using spaces and special characters within a rawmsg string pattern can result in inconsistent search results. To avoid this, either encapsulate single words with quotation marks as noted above or use the AND operator between words. For example:

    • Use "incapsula" AND "impreva" instead of "incapsula impreva".

    • Use 'username' 'admin' instead of 'username:admin'.

  • Using : (contains) instead of = (exact match) is recommended for inexperienced users.