ES|QL

ES|QL in the real world

ES|QL in the real world: from raw log to decision. This isn't a function catalog but the queries an engineer actually keeps on hand — SOC detection (beaconing, DNS exfiltration, impossible travel), statistical observability (MAD, z-score, SLO), and predictive capacity planning. The output you see IS the insight, built with recent functions like INLINESTATS, CATEGORIZE, and ST_DISTANCE that are nearly impossible to find documented in French.

21 featured snippets

Back to the Data Lab