EQL - query language for event data in Elasticsearch #59686
Labels
:Analytics/EQL
EQL querying
experimental/beta
release highlight
Team:QL (Deprecated)
Meta label for query languages team
v7.9.0
Meta issue consolidating the EQL functionality released in Elasticsearch 7.9 as experimental.
EQL or Event Query Language is a declarative language dedicated for identifying patterns and relationships between events.
Consider using EQL if you:
A good intro on EQL and its purpose is available here. The language reference can be found at this address while EQL on Elasticsearch is explained at length through a dedicated chapter.
This release includes the following features:
An in-depth discussion of EQL in ES scope can be found at #49581.
Full history available here.
High-level tasks
The text was updated successfully, but these errors were encountered: