The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Use transforms to define how search results are returned and displayed

Prev Next

Transforms are an important component of TQL that allow you to manipulate data before search results are returned and displayed. Transforms are separated from the rest of your query by the pipe symbol (|). Queries in Helix can include multiple transforms or no transforms.

The following transforms can be used in TQL queries.

  • groupby — Returns the unique values for a specified field and groups them together based on their frequency. You can use this transform to determine which specific field values are most or least active in your environment and to see how those values relate to other values for the same field.

  • sort — Determines how to arrange events returned in a TQL search.

Unless otherwise specified, all transforms support named arguments using a key/value pair syntax. For example, the following groupby transform:

rawmsg:* | groupby srcipv4 10 1000

could also be written:

rawmsg:* | groupby field = srcipv4 limit = 10 threshold:1000

These two statements are equivalent in functionality and support. Using one or the other comes down to personal preference. When using the key/value pair syntax, the order of the arguments does not matter, the colon (:) and equal (=) operators are interchangeable, and spaces around them, or lack thereof, do not matter.