Nest ES|QL queries using subqueries
A subquery is a complete ES|QL query wrapped in parentheses, nested inside another query. Each subquery runs independently and cannot reference columns from the outer query.
You can use subqueries in two places:
- In a
FROMcommand: each subquery runs its own pipeline and its rows are combined into the outer result set. - With
INorNOT IN: the subquery returns one column, or a tuple of columns matched by position, and can appear inWHERE. It can also appear inEVAL, and the per-aggregateWHEREofSTATSandINLINE STATS.
A subquery starts with one of the following source commands:
FROM: read from an index pattern.TS: read from a time series index pattern.ROW: synthesize rows from literal values.
The source command can be followed by zero or more piped processing commands:
CHANGE_POINTCOMPLETIONDISSECTDROPENRICHEVALGROKINLINE STATSKEEPLIMITLOOKUP JOINMV_EXPANDRENAMERERANKSAMPLESORTSTATSWHERE
- Use subqueries in a
FROMcommand: combine result sets from independently processed sources. - Use subqueries with
INandNOT IN: filter or evaluate rows against another query.