The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Understanding the rule language

Prev Next

In Helix, incoming events are tested against rules, and if the conditions of the rule are met it triggers an alert. There are different conditions you can use in a rule to test against incoming events: fields, correlation, deviation, and cardinality.

All rules start with the global parameters that define the rule: id, version, and name. The rule continues with a correlation conditions, which define the criteria for the rule to trigger an alert. This consists of one or more items that must be matched and correlated for the rule to fire.

Rules can test for specific values in individual event fields. For example, a rule could look for the srcipv4 field to equal the fixed address 10.0.0.1: srcipv4==10.0.0.1. You can use Boolean operators, for example or and and, to build more complex rules. In addition to testing fields in a single event, you can use rules to correlate between events. A correlation groups events together that have the same value for one or more defined fields. For example, the rule could look for a certain number of failed log on attempts from the same source IP address. The rule groups events by each unique IP address, and triggers if any of the groups reaches threshold you define, for example, ten failed log on attempts in a minute.

Rules are written in YAML and have the following parameters:

Name

Type

Required

Default

Description

id

String

Yes

Not applicable

The unique identifier for the rule.

name

String

Yes

Not applicable

The name of the rule.

version

Number

Yes

Not applicable

The version of the rule. If you edit the rule, the version number is incremented.

output

List<Output>

No

Not applicable

An optional list of field values to add to the alert generated by the rule.

metadata

Object

No

Not applicable

An optional object consisting of name/value pairs to associate with the rule.