To help you create TQL search queries, Helix suggests color-coded fields as you type. When you select a function, a pop-up shows the syntax so you know what values to use with the function. On the Search page, turn on the TQL Syntax toggle to see some common operators and functions you will need to create search queries. Click one of the query examples to add it to the search bar, or for more information on TQL click View Documentation to open the Trellix Helix TQL Reference Guide.
In the following example, consider each part of the search query has(class) | groupby class 10:
has: The function is highlighted. The pop-up gives a brief description of the function and what values it takes, as well as example queries and results..png)
has(class): When you type an open parentheses a closing parentheses is automatically added. This applies to other punctuation pairs. As you type class, all fields that match are also listed. You can use tab to autocomplete..png)
has(class) | groupby: The groupby function is highlighted. The pop-up gives a brief description of the function and what values it takes, as well as example queries and results..png)
has(class) | groupby class: As you type class, all fields that match are also listed..png)
has(class) | groupby class 10: 10 limits the results to the 10 most frequent classes..png)