To run a search in Helix Enterprise, enter a search query written using Trellix Query Language (TQL). See the TQL Reference Guide for more information.
After you have run one query, you can use pivoting to refine the query or create a new query. See Pivoting from event data.
Note
Organization-related features are included in the federated view, described in Federated view.
To run a search:
Enter a search query using TQL syntax. See the TQL Reference Guide for more information. You can select Syntax Help underneath the search bar to get help entering a TQL search query.
Select Index Search or Archive Search from the search drop-down menu.
Select a time range over which you want to search by clicking the calendar icon. See Selecting a date range for the search. If you do not select a date range, archive search will search all of your data, which may take a very long time.
Note
The archive search end time cannot be within 3 hours of the current time.
Select the sensor (CB) for the data you want to search. See Selecting a sensor (CB) for the search.
Click the
icon on the right end of the search bar. If you selected an index search, the search starts.If you selected an archive search, a confirmation message provides the search ID, which you can use to track the progress of the search on the Archive Searches page. The progress is also shown in the search bar.
(Optional). Use the Run Archive Search window to limit results to a specified number of results or minutes.
Note
The actual archive search time may differ from the End search after value, based on the current search load.
Click Run Search.
Note
A limited number of archive searches can run concurrently. The upper right corner of the Run Archive Search window shows you how many more you can run. You can still create archive searches after the limit is reached, but the archive searches will be queued until a currently running archive search completes.
To review and use the search results, see Using search results.