stack es eql search cli command

Auth required Idempotent Scope: global
elastic stack es eql search --query <query> --index <index> [options]
		

Get EQL search results.

Behaviour flags:

--dry-run — validate all inputs and exit without performing any action

--query string required
EQL query you wish to run.
--index string required

Comma-separated list of index names to scope the operation

Repeatable: pass --index multiple times to supply more than one value

--allow-no-indices
A setting that does two separate checks on the index expression. If false, the request returns an error (1) if any wildcard expression (including _all and *) resolves to zero matching indices or (2) if the complete set of resolved indices, aliases or data streams is empty after all expressions are evaluated. If true, index expressions that resolve to no indices are allowed and the request returns an empty result.
--allow-partial-search-results
Allow query execution also in case of shard failures. If true, the query will keep running and will return results based on the available shards. For sequences, the behavior can be further refined using allow_partial_sequence_results
--allow-partial-sequence-results
This flag applies only to sequences and has effect only if allow_partial_search_results=true. If true, the sequence query will return results based on the available shards, ignoring the others. If false, the sequence query will return successfully, but will always have empty results.
--expand-wildcards enum

Whether to expand wildcard expression to concrete indices that are open, closed or both.

Values: all, open, closed, hidden, none

Repeatable: pass --expand-wildcards multiple times to supply more than one value

--ccs-minimize-roundtrips
Indicates whether network round-trips should be minimized as part of cross-cluster search requests execution
--ignore-unavailable
If false, the request returns an error if it targets a concrete (non-wildcarded) index, alias, or data stream that is missing, closed, or otherwise unavailable. If true, unavailable concrete targets are silently ignored.
--keep-alive string
--keep-on-completion
--wait-for-completion-timeout string
--case-sensitive
--event-category-field string
Field containing the event classification, such as process, file, or network.
--tiebreaker-field string
Field used to sort hits with the same timestamp in ascending order
--timestamp-field string
Field containing event timestamp.
--fetch-size number
Maximum number of events to search at a time for sequence queries.
--filter string

Query, written in Query DSL, used to filter the events on which the EQL query runs.

Repeatable: pass --filter multiple times to supply more than one value

--size number
For basic queries, the maximum number of matching events to return. Defaults to 10
--fields string

Array of wildcard (*) patterns. The response returns values for field names matching these patterns in the fields property of each hit.

Repeatable: pass --fields multiple times to supply more than one value

--result-position enum

Values: tail, head

--runtime-mappings string
--max-samples-per-key number
By default, the response of a sample query contains up to 10 samples, with one sample per unique set of join keys. Use the size parameter to get a smaller or larger set of samples. To retrieve more than one sample per set of join keys, use the max_samples_per_key parameter. Pipes are not supported for sample queries.
--error-trace
When set to true Elasticsearch will include the full stack trace of errors when they occur.
--filter-path string

Comma-separated list of filters in dot notation which reduce the response returned by Elasticsearch.

Repeatable: pass --filter-path multiple times to supply more than one value

--human
When set to true will return statistics in a format suitable for humans. For example "exists_time": "1h" for humans and "exists_time_in_millis": 3600000 for computers. When disabled the human readable values will be omitted. This makes sense for responses being consumed only by machines.
--pretty
If set to true the returned JSON will be "pretty-formatted". Only use this option for debugging only.
--input-file string
path to a JSON file to use as command input
--dry-run
validate all inputs and exit without performing any action (preview changes without applying them)
--json

output as JSON