New

The executive guide to generative AI

Read more
Loading

Use ES|QL in Elastic Security

Elastic Stack Serverless

You can use ES|QL in Elastic Security to investigate events in Timeline and create detection rules. Use the Elastic AI Assistant to build ES|QL queries, or answer questions about the ES|QL query language.

You can use ES|QL in Timeline to filter, transform, and analyze event data stored in Elasticsearch. To start using ES|QL, open the ES|QL tab. To learn more, refer to Investigate events in Timeline.

Use the ES|QL rule type to create detection rules using ES|QL queries. The ES|QL rule type supports aggregating and non-aggregating queries. To learn more, refer to Create an ES|QL rule.

Use the Elastic AI Assistant to build ES|QL queries, or answer questions about the ES|QL query language. To learn more, refer to AI Assistant.