Open saeed-mcu opened 7 months ago
Have you looked at PPL: https://opensearch.org/docs/latest/search-plugins/sql/ppl/syntax/ ?
Hi @msfroh , thanks for your answer. I've seen PPL before but that's not what I talked about. In EQL, there are many functions and expressions that are very useful in attack detection and without them it is not possible
For example, the following EQL is meant to match a sequence of events that:
user.name
field values15m
(15 minutes) of the first matching event
sequence by user.name with maxspan=15m
[ file where file.extension == "exe" ]
[ process where true ]
@anirudha any thoughts on this proposal?
@opensearch-project/admin -- Can we please reassign this to the opensearch-project/sql repository? The requested capability sounds like something that should be supported by PPL. Thanks
Event Query Language (EQL) is a query language for event-based time series data, such as logs, metrics, and traces. Is there any way , I can use EQL in opensearch for searching logs ?
Something like EQL search in ElasticSearch. It is very useful for security analytics and Correlation rule.