The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Traffic validation and network visibility check TQL queries

Prev Next

The following TQL queries can be used for traffic validation and network visibility.

Full scope of capture query (classes observed)
| groupby [class]
Full scope of capture query (user to internet, data center to internet, user to data center)
| groupby [srcisp,dstisp]
Network Security (NX) alerts triggered by a local deployment test, grouped by device name and device ID

Alerts triggered by local deployment tests that are run from the Network Security appliance Web UI or CLI.

class=fireeye_nx_alert has(domain) has(url) domain:/fedeploycheck/ | groupby [devicename,deviceid]
All classes but one referencing destination network ports

All classes (except fireeye_nx L7 network metadata) that reference destination ports 80, 8080, or 443) and grouped by class, destination port, and protocol.

!class:fireeye_nx dstport:[80,8080,443] | groupby [class,dstport,protocol]
Citrix connections grouped by country of origin

Note

This example includes a reference to a list of external Citrix servers.

class:fireeye_nx dstipv4:$external_citrix_servers connstate:"sf" | groupby srccountry 200
Traffic capture bi-directional traffic checks (class agnostic)

List of internal IPs on a subnet

class:"bro_*" srcipv4:"<SUBNET ADDRESS/CIDR>" srcisp:"private ip address lan"| groupby srcipv4 500

List of incoming connections to internal addresses from a non-internal source

class:"bro_*" dstipv4:"<SUBNET ADDRESS/CIDR>" srcisp!:"private ip address lan" | groupby srcipv4 500

List of connections from an internal subnet by source and destination ISP

class:"bro_*" srcipv4:"<SUBNET ADDRESS/CIDR>" | groupby [srcisp,dstisp]

List of incoming connections to internal addresses from a non-internal source by source and destination ISP

class:"bro_*" dstipv4:"<SUBNET ADDRESS/CIDR>" srcisp!:"private ip address lan"  | groupby [srcisp,dstisp]
HTTP Traffic check pivot from specific connection ID
class=bro_http connectionid=<CONNECTION ID> | groupby [dstisp,srcisp]
Wilderness rule firing check
has:detect_rulematches | groupby detect_rulenames
Cloud MVX Submission OS Change Report from Cloud Collector (faf and bespin enablement)
class:fireeye_faf has:virus
Number of events in one hour by log type

Compares the number of events received in one hour from each log source.

start:"2014-03-14 15:00:00" end:"2014-03-14 16:00:00" | groupby class
start:"2 hours ago" end:"1 hour ago"| groupby class