The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Search query hints

Prev Next

To help you create TQL search queries, Helix suggests color-coded fields as you type. When you select a function, a pop-up shows the syntax so you know what values to use with the function. On the Search page, turn on the TQL Syntax toggle to see some common operators and functions you will need to create search queries. Click one of the query examples to add it to the search bar, or for more information on TQL click View Documentation to open the Trellix Helix TQL Reference Guide.

In the following example, consider each part of the search query has(class) | groupby class 10:

  1. has: The function is highlighted. The pop-up gives a brief description of the function and what values it takes, as well as example queries and results.

    Helix-search-hint-Step-1.png

  2. has(class): When you type an open parentheses a closing parentheses is automatically added. This applies to other punctuation pairs. As you type class, all fields that match are also listed. You can use tab to autocomplete.

    Helix-search-hint-Step-2.png

  3. has(class) | groupby: The groupby function is highlighted. The pop-up gives a brief description of the function and what values it takes, as well as example queries and results.

    Helix-search-hint-Step-3.png

  4. has(class) | groupby class: As you type class, all fields that match are also listed.

    Helix-search-hint-Step-4.png

  5. has(class) | groupby class 10: 10 limits the results to the 10 most frequent classes.

    Helix-search-hint-Step-5.png