Skip to content

Conversation

@jrodewig
Copy link
Contributor

@jrodewig jrodewig commented Mar 5, 2020

7.x backport of #52821

* [DOCS] Document `any` keyword in EQL syntax

Adds documentation for the `any` keyword to the EQL syntax docs.

Includes:

* Definition of an event type and its relationship to the event type
  field.
* Example matching all event types using `any` keyword
* Example matching event types beginning with a digit
* Example using `any` with `where true`

* Remove references to `event_type_field` default

* Reuse "Events starting with digits" section

* Updates for #53073
@jrodewig jrodewig added >docs General docs changes :Analytics/EQL EQL querying labels Mar 5, 2020
@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-docs (>docs)

@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-search (:Search/EQL)

@jrodewig jrodewig merged commit e46bb54 into elastic:7.x Mar 5, 2020
@jrodewig jrodewig deleted the backport__52821-7x branch March 5, 2020 10:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

:Analytics/EQL EQL querying backport >docs General docs changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants