# Can i write elastic query using KQL or Lucene

**URL:** <https://discuss.elastic.co/t/can-i-write-elastic-query-using-kql-or-lucene/227337>\
**Category:** SIEM\
**Created:** [April 9, 2020, 1:57pm UTC](https://discuss.elastic.co/t/can-i-write-elastic-query-using-kql-or-lucene/227337 "2020-04-09T13:57:54Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [April 10, 2020, 2:02pm UTC](https://discuss.elastic.co/t/can-i-write-elastic-query-using-kql-or-lucene/227337/2 "2020-04-10T14:02:06Z")

</div>

I gave a more thorough answer to you in your previous post:

> [@Adding a condition in detection engine](https://discuss.elastic.co/t/adding-a-condition-in-detection-engine/227331/2):
>
> As a filter you can. It's a bit different because we are using more visual builders and tucking more of the JSON under the covers but we have buttons such as the "Edit as Query DSL" for advanced usage to see what the queries look like or to edit them directly. It's always best to try and use KQL with the filters visually where it makes things more readable if you're translating from a watcher like so below: You can see that I'm saying find all the exist…

But yes, you should also be able to use plain lucene if you really want to by sliding off KQL:

 ![Screen Shot 2020-04-10 at 7.57.01 AM](https://us1.discourse-cdn.com/elastic/original/3X/9/4/94d0635a40d97c83264bb119b3f22cd7f5165f90.png)

I would recommend you trying to keep it to KQL and filters before utilizing lucene as it's a better experience and more readable and it translated to Elastic Search filters which are better performance wise than Lucene.

For example, this shows what a Lucene query would translate to:

> <https://github.com/elastic/kibana/blob/7.6/x-pack/legacy/plugins/siem/server/lib/detection_engine/signals/get_filter.test.ts#L76-L94>

And that's not the same as what the KQL translates to:

> <https://github.com/elastic/kibana/blob/7.6/x-pack/legacy/plugins/siem/server/lib/detection_engine/signals/get_filter.test.ts#L52-L74>

Which at the time of this writing is using filters which should be cached:

> **[Query and filter context | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-filter-context.html#filter-context)**

---

_[View the full topic](https://discuss.elastic.co/t/can-i-write-elastic-query-using-kql-or-lucene/227337)._
