OpenSearch
OpenSearch copied to clipboard
Event Query Language (EQL) for Opensearch
Event Query Language (EQL) is a query language for event-based time series data, such as logs, metrics, and traces. Is there any way , I can use EQL in opensearch for searching logs ?
Something like EQL search in ElasticSearch. It is very useful for security analytics and Correlation rule.
@opensearch-project/plugins , can you transfer the issue to core for further discussion
Can someone from @opensearch-project/sql team add your comments?
[Triage - attendees 1 2 3 4] @saeed-mcu Thanks for filing. We do not support Event Query Language today. However, have you looked at the features offered by the https://github.com/opensearch-project/security-analytics plugin? Also the https://github.com/opensearch-project/sql plugin offers additional query options that may be useful here as well.