Aliases

Prev Next

TQL recognizes aliases for field names. The alias searches for all fields that are designated as corresponding to that alias. Using an alias allows you to search for multiple fields at the same time without knowing the exact field name of each field. An alias will match on any field that it represents.

Caution

Trellix recommends using aliases sparingly. While this type of query may be useful, it is a time-intensive query to run because the search must look for every field that the alias represents.

Note

If you want to search for specific multiple field names, use a list instead. For more information, see Subsearch and variable expansion.

Aliases include:

For example:

~hash=[hash or MD5 or SHA1 or SHA256 or SHA512]