# Can i write elastic query using KQL or Lucene

**URL:** <https://discuss.elastic.co/t/can-i-write-elastic-query-using-kql-or-lucene/227337>\
**Category:** SIEM\
**Created:** [April 9, 2020, 1:57pm UTC](https://discuss.elastic.co/t/can-i-write-elastic-query-using-kql-or-lucene/227337 "2020-04-09T13:57:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Saurabh\_Singh1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saurabh_singh1/32/63178_2.png) [@Saurabh\_Singh1](https://discuss.elastic.co/u/Saurabh_Singh1)\
**Post date:** [April 9, 2020, 1:57pm UTC](https://discuss.elastic.co/t/can-i-write-elastic-query-using-kql-or-lucene/227337/1 "2020-04-09T13:57:55Z")

</div>

I was trying to replicate watcher functionality using SIEM detection rule. In watcher i can write elastic query, but can i perform that using detection rule ? Please help.

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [April 10, 2020, 2:02pm UTC](https://discuss.elastic.co/t/can-i-write-elastic-query-using-kql-or-lucene/227337/2 "2020-04-10T14:02:06Z")

</div>

I gave a more thorough answer to you in your previous post:

> [@Adding a condition in detection engine](https://discuss.elastic.co/t/adding-a-condition-in-detection-engine/227331/2):
>
> As a filter you can. It's a bit different because we are using more visual builders and tucking more of the JSON under the covers but we have buttons such as the "Edit as Query DSL" for advanced usage to see what the queries look like or to edit them directly. It's always best to try and use KQL with the filters visually where it makes things more readable if you're translating from a watcher like so below: You can see that I'm saying find all the exist…

But yes, you should also be able to use plain lucene if you really want to by sliding off KQL:

 ![Screen Shot 2020-04-10 at 7.57.01 AM](https://us1.discourse-cdn.com/elastic/original/3X/9/4/94d0635a40d97c83264bb119b3f22cd7f5165f90.png)

I would recommend you trying to keep it to KQL and filters before utilizing lucene as it's a better experience and more readable and it translated to Elastic Search filters which are better performance wise than Lucene.

For example, this shows what a Lucene query would translate to:

> <https://github.com/elastic/kibana/blob/7.6/x-pack/legacy/plugins/siem/server/lib/detection_engine/signals/get_filter.test.ts#L76-L94>

And that's not the same as what the KQL translates to:

> <https://github.com/elastic/kibana/blob/7.6/x-pack/legacy/plugins/siem/server/lib/detection_engine/signals/get_filter.test.ts#L52-L74>

Which at the time of this writing is using filters which should be cached:

> **[Query and filter context | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-filter-context.html#filter-context)**

---

<div class="post-metadata">

**Author:** ![Saurabh\_Singh1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saurabh_singh1/32/63178_2.png) [@Saurabh\_Singh1](https://discuss.elastic.co/u/Saurabh_Singh1)\
**Post date:** [April 21, 2020, 4:19am UTC](https://discuss.elastic.co/t/can-i-write-elastic-query-using-kql-or-lucene/227337/3 "2020-04-21T04:19:44Z")

</div>

Thank you @Frank_Hassanabad that helped me .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2020, 4:19am UTC](https://discuss.elastic.co/t/can-i-write-elastic-query-using-kql-or-lucene/227337/4 "2020-05-19T04:19:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
