# Any interest in an Elasticsearch query language (EQL)?

**URL:** https://discuss.elastic.co/t/any-interest-in-an-elasticsearch-query-language-eql/2132
**Category:** Elasticsearch
**Created:** [June 8, 2015, 12:34pm UTC](https://discuss.elastic.co/t/any-interest-in-an-elasticsearch-query-language-eql/2132 "2015-06-08T12:34:04Z")
**Posts on this page:** 13
**Page:** 1

<div class="post-metadata">

### Author: ![metadave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/metadave/32/560_2.png) [@metadave](https://discuss.elastic.co/u/metadave)
#### Post date: [June 8, 2015, 12:34pm UTC](https://discuss.elastic.co/t/any-interest-in-an-elasticsearch-query-language-eql/2132/1 "2015-06-08T12:34:05Z")

</div>

Hello -

I spent a few hours getting a prototype of an Elasticsearch query language (dubbed "eql") up and running [0]. I'm posting here to see if there is any interest at all in a project like this.

Here are some examples that I have working:

```
query bank return 3 sort on balance asc, lastname desc;

query bank (balance, age, account_number)
  filter
    balance = 1110
    and (age = 31 or account_number=953)
  return 1;

index blogposts with post = '{"xyz":"this is a test", "foobar":100}';

get blogposts with post = "AU3Po0OOZX4PYDrqsDN1";

```

The github repo has a few animated gifs that demo eql running. If anyone has an interest in language design, I'd love to kick around some ideas on a full query language for Elasticsearch.

Cheers -  
Dave

[0] [https://github.com/metadave/eql](https://github.com/metadave/eql)

---

<div class="post-metadata">

### Author: ![jprante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jprante/32/44941_2.png) [@jprante](https://discuss.elastic.co/u/jprante)
#### Post date: [June 8, 2015, 3:28pm UTC](https://discuss.elastic.co/t/any-interest-in-an-elasticsearch-query-language-eql/2132/2 "2015-06-08T15:28:07Z")

</div>

Cool!

Looks like this is for working from a remote command line console?

I'm interested in these points:

- the language parser should also be implemented as a plugin so it can be used over HTTP.

- the "query"/"get" part should be addressable by a separate end point than the administrative commands so it can be used safely without the risk of modifying/deleting data ("read only mode")

- reuse of query results in subsequent queries (assigning results to variables probably)

- presenting results in CSV, JSON arrays, or XML, like in my plugins [https://github.com/jprante/elasticsearch-xml](https://github.com/jprante/elasticsearch-xml) or [https://github.com/jprante/elasticsearch-arrayformat](https://github.com/jprante/elasticsearch-arrayformat)

---

<div class="post-metadata">

### Author: ![metadave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/metadave/32/560_2.png) [@metadave](https://discuss.elastic.co/u/metadave)
#### Post date: [June 8, 2015, 3:48pm UTC](https://discuss.elastic.co/t/any-interest-in-an-elasticsearch-query-language-eql/2132/3 "2015-06-08T15:48:16Z")

</div>

Thanks for the reply, Jörg.

The console exists in the EQL repo (using JLine), but the main Antlr4 parser could be packaged via Maven separately. I used a similar approach on a parser at work, and it allows me to try out the library via command line/script.

Regarding your points (and apologies for the awkward inline format below):

- the language parser should also be implemented as a plugin so it can be used over HTTP.

no problem here, it boils down to a Java Maven dependency to evaluate a query.

- the "query"/"get" part should be addressable by a separate end point than the administrative commands so it can be used safely without the risk of modifying/deleting data ("read only mode")

Agreed, but I wonder if something like:

```
connect readonly foo:9300; 

```

might look nicer to a user. In a previous parser, I made a database connection optional for each query command for exactly this reason.

- reuse of query results in subsequent queries (assigning results to variables probably)

This is doable, but not in my prototype at the moment.

- presenting results in CSV, JSON arrays, or XML, like in my plugins [https://github.com/jprante/elasticsearch-xml](https://github.com/jprante/elasticsearch-xml) or [https://github.com/jprante/elasticsearch-arrayformat](https://github.com/jprante/elasticsearch-arrayformat)

Excellent idea, I'll take a look at your plugins (woot Apache 2 license!)

Cheers -  
Dave

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [June 9, 2015, 2:20am UTC](https://discuss.elastic.co/t/any-interest-in-an-elasticsearch-query-language-eql/2132/4 "2015-06-09T02:20:19Z")

</div>

Very nice idea!

---

<div class="post-metadata">

### Author: ![otisg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/otisg/32/492_2.png) [@otisg](https://discuss.elastic.co/u/otisg)
#### Post date: [June 10, 2015, 1:56am UTC](https://discuss.elastic.co/t/any-interest-in-an-elasticsearch-query-language-eql/2132/5 "2015-06-10T01:56:41Z")

</div>

Hi,

Interesting. We have an SQL layer on top of ES, though it's not on Github (yet?).  
Does eql imply having to learn a new language structure?

## Otis

Monitoring \* Alerting \* Anomaly Detection \* Centralized Log Management  
Solr & Elasticsearch Support \* [http://sematext.com/](http://sematext.com/)

---

<div class="post-metadata">

### Author: ![metadave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/metadave/32/560_2.png) [@metadave](https://discuss.elastic.co/u/metadave)
#### Post date: [June 10, 2015, 3:06am UTC](https://discuss.elastic.co/t/any-interest-in-an-elasticsearch-query-language-eql/2132/6 "2015-06-10T03:06:59Z")

</div>

> Does eql imply having to learn a new language structure?

Yes. It's specifically designed to _not_ look like SQL. I worked at a nosql database company in the past, and mapping SQL to non-sql data stores was awkward. The tradeoff is/was to make a language that sounds as natural as possible.

Cheers -  
Dave

---

<div class="post-metadata">

### Author: ![jprante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jprante/32/44941_2.png) [@jprante](https://discuss.elastic.co/u/jprante)
#### Post date: [June 10, 2015, 7:00am UTC](https://discuss.elastic.co/t/any-interest-in-an-elasticsearch-query-language-eql/2132/7 "2015-06-10T07:00:48Z")

</div>

+1 for not using SQL.

Even for RDBMS, SQL is flawed, inconsistent, not easy to use. The "Cobol of the relational world".

For non-sql data, there is no standard, but maybe something will silently evolve - the community decides what will stand the test of time.

---

<div class="post-metadata">

### Author: ![lukas\_vlcek](https://avatars.discourse-cdn.com/v4/letter/l/dfb087/32.png) [@lukas\_vlcek](https://discuss.elastic.co/u/lukas_vlcek)
#### Post date: [June 10, 2015, 10:20am UTC](https://discuss.elastic.co/t/any-interest-in-an-elasticsearch-query-language-eql/2132/8 "2015-06-10T10:20:40Z")

</div>

Hi Dave,

nice! Are there any EQL examples that would be equal to more complicated ES queries? Like nested aggregations? Filtered query with non-trivial query and filter parts? I would like to get an idea of how this would look like - did not find anything like this in your repo.

Regards,  
Lukas

---

<div class="post-metadata">

### Author: ![metadave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/metadave/32/560_2.png) [@metadave](https://discuss.elastic.co/u/metadave)
#### Post date: [June 12, 2015, 3:11pm UTC](https://discuss.elastic.co/t/any-interest-in-an-elasticsearch-query-language-eql/2132/9 "2015-06-12T15:11:30Z")

</div>

Hello Lukas -

Since it's only a prototype, the examples in the repo are all I have at the moment. Do you have any example queries in mind that are more complex that I could model after?

Thanks for taking a look!  
Dave

---

<div class="post-metadata">

### Author: ![metadave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/metadave/32/560_2.png) [@metadave](https://discuss.elastic.co/u/metadave)
#### Post date: [June 13, 2015, 1:34am UTC](https://discuss.elastic.co/t/any-interest-in-an-elasticsearch-query-language-eql/2132/10 "2015-06-13T01:34:45Z")

</div>

Actually, I see some examples in the docs. I'll kick those around a bit and see what I can come up with.

Have a great weekend -  
Dave

---

<div class="post-metadata">

### Author: ![metadave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/metadave/32/560_2.png) [@metadave](https://discuss.elastic.co/u/metadave)
#### Post date: [June 14, 2015, 2:18pm UTC](https://discuss.elastic.co/t/any-interest-in-an-elasticsearch-query-language-eql/2132/11 "2015-06-14T14:18:54Z")

</div>

Ok, here's what _simple_ aggregates look like:

```
  query bank 
     aggregate min_bal = min(balance), max_bal = max(balance);

   (truncated results)
   "aggregations" : {
      "max_bal" : {
        "value" : 49989.0
      },
      "min_bal" : {
        "value" : 1011.0
      }
    }

    // filter + aggregation
    query bank 
      filter age = 20 
      aggregate foo = min(balance), bar = max(balance);

   (truncated results)
    "aggregations" : {
       "foo" : {
       "value" : 1650.0
      },
    "bar" : {
       "value" : 49568.0
     }
  }

```

I'll keep chugging ahead and implement other pieces, time permitting. I won't post progress on this thread, but I'll keep the README updated with new statements here: [https://github.com/metadave/eql](https://github.com/metadave/eql)

Cheers -  
Dave

---

<div class="post-metadata">

### Author: ![PatrickKik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrickkik/32/619_2.png) [@PatrickKik](https://discuss.elastic.co/u/PatrickKik)
#### Post date: [July 29, 2015, 5:20am UTC](https://discuss.elastic.co/t/any-interest-in-an-elasticsearch-query-language-eql/2132/12 "2015-07-29T05:20:39Z")

</div>

I like the idea. Good luck!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 11:58pm UTC](https://discuss.elastic.co/t/any-interest-in-an-elasticsearch-query-language-eql/2132/13 "2017-07-05T23:58:28Z")

</div>


