Nest ES|QL queries using subqueries

A subquery is a complete ES|QL query wrapped in parentheses, nested inside another query. Each subquery runs independently and cannot reference columns from the outer query.

You can use subqueries in two places:

  • In a FROM command: each subquery runs its own pipeline and its rows are combined into the outer result set.
  • With IN or NOT IN: the subquery returns one column, or a tuple of columns matched by position, and can appear in WHERE. It can also appear in EVAL, and the per-aggregate WHERE of STATS and INLINE STATS .

A subquery starts with one of the following source commands:

  • FROM: read from an index pattern.
  • TS: read from a time series index pattern.
  • ROW: synthesize rows from literal values.

The source command can be followed by zero or more piped processing commands: