Fields

Prev Next

Note

Except for the rawmsg, program, and meta_omh fields, values for string fields are treated as lowercase.

Field names in TQL queries consist of a string of letters and numbers. Each distinct field is the string up to a white space or a string within quotation marks. Field names are determined by the taxonomy. They are not case sensitive and can be either lowercase or uppercase.

Fields containing strings that have not been normalized (that is, parsed using an Trellix Helix parser against the taxonomy) will match only on the entire contents of the field. All parsed fields (that is, fields designated by an Trellix Helix parser against the taxonomy) will match on partial values.

The following fields are common in Trellix Helix events, (whether part of a class or metaclass):

  • _metadata_.customer_id

  • rawmsghostname

  • rawmsg

  • class

  • program

If the field does not apply to that event, that field is still present but has no value.