Use a list and refer to it instead of repeatedly using arrays.
Regular expression (regex) operations can be performed against a maximum of 50,000 events for each search in Helix. To perform regex operations against larger datasets, you must filter search results to fewer than 50,000 events. Otherwise, the search will not complete successfully.
Encapsulate all string patterns with single or double quotation marks to help ensure that Helix accurately interprets the string. For example:
Using spaces and special characters within a
rawmsgstring pattern can result in inconsistent search results. To avoid this, either encapsulate single words with quotation marks as noted above or use theANDoperator between words. For example:count>"4"eventtime>'2022-04-07T01:10:50:000Z'
Using spaces and special characters within a
rawmsgstring pattern can result in inconsistent search results. To avoid this, either encapsulate single words with quotation marks as noted above or use theANDoperator between words. For example:Use
"incapsula" AND "impreva"instead of"incapsula impreva".Use
'username' 'admin'instead of'username:admin'.
Using
:(contains) instead of=(exact match) is recommended for inexperienced users.
Search best practices
- Updated on Sep 13, 2026
- Published on Sep 12, 2026
- 1 minute(s) read
Was this article helpful?