Helix search uses a single query language to run searches on data that was collected and stored in Helix, as well as data from connected technologies such as other Trellix products and third-party products. A single search interface allows for customizable queries that pull in relevant data to view and process. You can search for events from any page of the Helix UI with the search icon (
) in the top navigation bar. The query remains available as you move between UI pages so you can add terms to the query to refine your search. All searches are asynchronous and run in the background.
For raw events, Helix can search for matching strings.
For parsed events that are normalized according to the Helix taxonomy, Helix can search for common data across all events from a variety of log sources.
Search finds specific events associated with alerts. Search can also be used as a starting point for threat hunting, which is a proactive and iterative approach to detecting malicious, suspicious, or risky activities that evaded detection by existing tools. It lets you determine whether techniques and tactics you suspect, hypothesize about, or heard about are in fact compromising your environment.
Note
Helix Index Search returns a maximum of 10,000 results. Archive Search returns a maximum of 20,000 results. The combined maximum for Helix Index Search and Archive Search is 30,000 results.