Skip to content

Conversation

jrodewig
Copy link
Contributor

Adds a basic tutorial and example for performing an EQL search.

I plan to add additional sections (specifying timestamp/event type, joins, pagination) with
future PRs. See #51057.

Also adds missing experimental::[] macro to the EQL requirements page.

@jrodewig jrodewig added >docs General docs changes :Analytics/EQL EQL querying labels Jan 28, 2020
@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-search (:Search/EQL)

@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-docs (>docs)

@jrodewig jrodewig marked this pull request as ready for review January 29, 2020 15:29
I plan to add additional sections to this page with future PRs: * Specify timestamp and event type fields * Specify a join key field * Filter using query DSL * Paginate a large response See #51057.
Copy link
Contributor

@aleksmaus aleksmaus left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@jrodewig jrodewig merged commit be8ae97 into elastic:master Feb 12, 2020
@jrodewig jrodewig deleted the docs__search-eql-tutorial branch February 12, 2020 13:40
jrodewig added a commit that referenced this pull request Feb 12, 2020
I plan to add additional sections to this page with future PRs: * Specify timestamp and event type fields * Specify a join key field * Filter using query DSL * Paginate a large response See #51057.
@jrodewig
Copy link
Contributor Author

Backport commits

master be8ae97
7.x 20453d3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

:Analytics/EQL EQL querying >docs General docs changes

4 participants