﻿---
title: stack es eql search cli command
description: Get EQL search results. Behaviour flags: --dry-run — validate all inputs and exit without performing any action 
url: https://www.elastic.co/elastic/docs-builder/docs/4075/reference/elastic-cli/cli/stack/es/eql/search
applies_to:
  - Elastic Cloud Serverless: Preview
  - Elastic Stack: Preview
---

# stack es eql search cli command
<cli-modifiers>
</cli-modifiers>

```bash
elastic stack es eql search --query <query> --index <index> [options]
```

Get EQL search results.
**Behaviour flags:**
`--dry-run` — validate all inputs and exit without performing any action

## Options

<definitions>
  <definition term="--query string required">
    EQL query you wish to run.
  </definition>
  <definition term="--index string required">
    Comma-separated list of index names to scope the operation
    **Repeatable:** pass `--index` multiple times to supply more than one value
  </definition>
  <definition term="--allow-no-indices">
    A setting that does two separate checks on the index expression.
    If `false`, the request returns an error (1) if any wildcard expression
    (including `_all` and `*`) resolves to zero matching indices or (2) if the
    complete set of resolved indices, aliases or data streams is empty after all
    expressions are evaluated. If `true`, index expressions that resolve to no
    indices are allowed and the request returns an empty result.
  </definition>
  <definition term="--allow-partial-search-results">
    Allow query execution also in case of shard failures.
    If true, the query will keep running and will return results based on the available shards.
    For sequences, the behavior can be further refined using allow_partial_sequence_results
  </definition>
  <definition term="--allow-partial-sequence-results">
    This flag applies only to sequences and has effect only if allow_partial_search_results=true.
    If true, the sequence query will return results based on the available shards, ignoring the others.
    If false, the sequence query will return successfully, but will always have empty results.
  </definition>
  <definition term="--expand-wildcards enum">
    Whether to expand wildcard expression to concrete indices that are open, closed or both.
    **Values:** all, open, closed, hidden, none
    **Repeatable:** pass `--expand-wildcards` multiple times to supply more than one value
  </definition>
  <definition term="--ccs-minimize-roundtrips">
    Indicates whether network round-trips should be minimized as part of cross-cluster search requests execution
  </definition>
  <definition term="--ignore-unavailable">
    If `false`, the request returns an error if it targets a concrete (non-wildcarded)
    index, alias, or data stream that is missing, closed, or otherwise unavailable.
    If `true`, unavailable concrete targets are silently ignored.
  </definition>
  <definition term="--keep-alive string">
  </definition>
  <definition term="--keep-on-completion">
  </definition>
  <definition term="--wait-for-completion-timeout string">
  </definition>
  <definition term="--case-sensitive">
  </definition>
  <definition term="--event-category-field string">
    Field containing the event classification, such as process, file, or network.
  </definition>
  <definition term="--tiebreaker-field string">
    Field used to sort hits with the same timestamp in ascending order
  </definition>
  <definition term="--timestamp-field string">
    Field containing event timestamp.
  </definition>
  <definition term="--fetch-size number">
    Maximum number of events to search at a time for sequence queries.
  </definition>
  <definition term="--filter string">
    Query, written in Query DSL, used to filter the events on which the EQL query runs.
    **Repeatable:** pass `--filter` multiple times to supply more than one value
  </definition>
  <definition term="--size number">
    For basic queries, the maximum number of matching events to return. Defaults to 10
  </definition>
  <definition term="--fields string">
    Array of wildcard (*) patterns. The response returns values for field names matching these patterns in the fields property of each hit.
    **Repeatable:** pass `--fields` multiple times to supply more than one value
  </definition>
  <definition term="--result-position enum">
    **Values:** tail, head
  </definition>
  <definition term="--runtime-mappings string">
  </definition>
  <definition term="--max-samples-per-key number">
    By default, the response of a sample query contains up to `10` samples, with one sample per unique set of join keys. Use the `size`
    parameter to get a smaller or larger set of samples. To retrieve more than one sample per set of join keys, use the
    `max_samples_per_key` parameter. Pipes are not supported for sample queries.
  </definition>
  <definition term="--error-trace">
    When set to `true` Elasticsearch will include the full stack trace of errors
    when they occur.
  </definition>
  <definition term="--filter-path string">
    Comma-separated list of filters in dot notation which reduce the response
    returned by Elasticsearch.
    **Repeatable:** pass `--filter-path` multiple times to supply more than one value
  </definition>
  <definition term="--human">
    When set to `true` will return statistics in a format suitable for humans.
    For example `"exists_time": "1h"` for humans and
    `"exists_time_in_millis": 3600000` for computers. When disabled the human
    readable values will be omitted. This makes sense for responses being consumed
    only by machines.
  </definition>
  <definition term="--pretty">
    If set to `true` the returned JSON will be "pretty-formatted". Only use
    this option for debugging only.
  </definition>
  <definition term="--input-file string">
    path to a JSON file to use as command input
  </definition>
  <definition term="--dry-run">
    validate all inputs and exit without performing any action (preview changes without applying them)
  </definition>
</definitions>


## Global Options

<definitions>
  <definition term="--json">
    output as JSON
  </definition>
</definitions>