stack es eql search cli command
elastic stack es eql search --query <query> --index <index> [options]
Get EQL search results.
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--querystringrequired- EQL query you wish to run.
--indexstringrequired-
Comma-separated list of index names to scope the operation
Repeatable: pass
--indexmultiple times to supply more than one value --allow-no-indices- A setting that does two separate checks on the index expression.
If
false, the request returns an error (1) if any wildcard expression (including_alland*) resolves to zero matching indices or (2) if the complete set of resolved indices, aliases or data streams is empty after all expressions are evaluated. Iftrue, index expressions that resolve to no indices are allowed and the request returns an empty result. --allow-partial-search-results- Allow query execution also in case of shard failures. If true, the query will keep running and will return results based on the available shards. For sequences, the behavior can be further refined using allow_partial_sequence_results
--allow-partial-sequence-results- This flag applies only to sequences and has effect only if allow_partial_search_results=true. If true, the sequence query will return results based on the available shards, ignoring the others. If false, the sequence query will return successfully, but will always have empty results.
--expand-wildcardsenum-
Whether to expand wildcard expression to concrete indices that are open, closed or both.
Values: all, open, closed, hidden, none
Repeatable: pass
--expand-wildcardsmultiple times to supply more than one value --ccs-minimize-roundtrips- Indicates whether network round-trips should be minimized as part of cross-cluster search requests execution
- If
false, the request returns an error if it targets a concrete (non-wildcarded) index, alias, or data stream that is missing, closed, or otherwise unavailable. Iftrue, unavailable concrete targets are silently ignored. --keep-alivestring--keep-on-completion--wait-for-completion-timeoutstring--case-sensitive--event-category-fieldstring- Field containing the event classification, such as process, file, or network.
--tiebreaker-fieldstring- Field used to sort hits with the same timestamp in ascending order
--timestamp-fieldstring- Field containing event timestamp.
--fetch-sizenumber- Maximum number of events to search at a time for sequence queries.
--filterstring-
Query, written in Query DSL, used to filter the events on which the EQL query runs.
Repeatable: pass
--filtermultiple times to supply more than one value --sizenumber- For basic queries, the maximum number of matching events to return. Defaults to 10
--fieldsstring-
Array of wildcard (*) patterns. The response returns values for field names matching these patterns in the fields property of each hit.
Repeatable: pass
--fieldsmultiple times to supply more than one value --result-positionenum-
Values: tail, head
--runtime-mappingsstring--max-samples-per-keynumber- By default, the response of a sample query contains up to
10samples, with one sample per unique set of join keys. Use thesizeparameter to get a smaller or larger set of samples. To retrieve more than one sample per set of join keys, use themax_samples_per_keyparameter. Pipes are not supported for sample queries. --error-trace- When set to
trueElasticsearch will include the full stack trace of errors when they occur. --filter-pathstring-
Comma-separated list of filters in dot notation which reduce the response returned by Elasticsearch.
Repeatable: pass
--filter-pathmultiple times to supply more than one value --human- When set to
truewill return statistics in a format suitable for humans. For example"exists_time": "1h"for humans and"exists_time_in_millis": 3600000for computers. When disabled the human readable values will be omitted. This makes sense for responses being consumed only by machines. --pretty- If set to
truethe returned JSON will be "pretty-formatted". Only use this option for debugging only. --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON