-
Notifications
You must be signed in to change notification settings - Fork 25.6k
Closed
Labels
:Analytics/EQLEQL queryingEQL querying>docsGeneral docs changesGeneral docs changesMetaTeam:DocsMeta label for docs teamMeta label for docs teamTeam:QL (Deprecated)Meta label for query languages teamMeta label for query languages team
Description
This is a meta issue to track the progress of documentation efforts for EQL support in Elasticsearch.
To monitor ongoing development, see #49581.
High-level content plan
- Top-level EQL page (intro + nav) [DOCS] Add top-level EQL docs page. Adds EQL requirements page. #51334
- EQL requirements [DOCS] Add top-level EQL docs page. Adds EQL requirements page. #51334
- Run an EQL search [DOCS] Add basic EQL search tutorial docs #51574
- Add a Beats tip [DOCS] Adds Beats tip to EQL search docs #53292
- Specify timestamp and event type fields [DOCS] Add parameter examples to EQL search tutorial #52953
- Filter using query DSL [DOCS] Add parameter examples to EQL search tutorial #52953
- Async search [DOCS] EQL: Document async search submits #56704
- EQL syntax reference [DOCS] Add EQL syntax page #51821
- EQL function reference
-
add[DOCS] EQL: Document math functions #55810 -
between[DOCS] EQL: Documentbetweenfunction #54950 -
cidrMatch[DOCS] EQL: DocumentcidrMatchfunction #54216 -
concat[DOCS] EQL: Documentconcatfunction #56239 -
divide[DOCS] EQL: Document math functions #55810 -
endsWith[DOCS] EQL: DocumentendsWithfunction #54521 -
indexOf[DOCS] EQL: DocumentindexOffunction #55071 -
length[DOCS] EQL: Documentlengthfunction #54225 -
match[DOCS] EQL: Documentmatchfunction #56134 -
modulo[DOCS] EQL: Document math functions #55810 -
multiply[DOCS] EQL: Document math functions #55810 -
number[DOCS] EQL: Documentnumberfunction #56770 -
startsWith[DOCS] EQL: DocumentstartsWithfunction #54518 -
string[DOCS] EQL: Documentstringfunction #55086 -
stringContains[DOCS] EQL: DocumentstringContainsfunction #54968 -
substring[7.x] [DOCS] EQL: Documentsubstringfunction (#53867) #54203 -
subtract[DOCS] EQL: Document math functions #55810 -
wildcard[DOCS] EQL: Documentwildcardfunction #54086
-
- EQL pipe reference [DOCS] EQL: Document
headandtailpipes #58673 - Limitations (EQL features not supported in ES) [DOCS] Add EQL limitations page #52001
- EQL search API documentation [DOCS] Document EQL search REST API #52384
Cleanup tasks
- Remove/swap
devadmonitions [DOCS] EQL: Prepare docs for release #59259 - Remove
ifdefstatements for including docs (cf. [DOCS] Include docs on permanently unreleased branches only #51743, [DOCS] Document EQL search REST API #52384) [DOCS] EQL: Prepare docs for release #59259
Metadata
Metadata
Assignees
Labels
:Analytics/EQLEQL queryingEQL querying>docsGeneral docs changesGeneral docs changesMetaTeam:DocsMeta label for docs teamMeta label for docs teamTeam:QL (Deprecated)Meta label for query languages teamMeta label for query languages team