# Elastic Lucene vs KQL vs DSL vs EQL

**URL:** <https://discuss.elastic.co/t/elastic-lucene-vs-kql-vs-dsl-vs-eql/302588>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [April 18, 2022, 4:26am UTC](https://discuss.elastic.co/t/elastic-lucene-vs-kql-vs-dsl-vs-eql/302588 "2022-04-18T04:26:48Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [April 18, 2022, 6:23am UTC](https://discuss.elastic.co/t/elastic-lucene-vs-kql-vs-dsl-vs-eql/302588/2 "2022-04-18T06:23:11Z")

</div>

Hi.  
KQL and Lucene query are end-user facing syntaxes designed for fast data entry by mostly unsophisticated users. They expose a subset of the engine’s matching features and if users don’t add appropriate brackets [can produce logic they didn’t expect.](https://discuss.elastic.co/t/explanation-of-terms-in-a-search/297523/6)  
DSL is a more formal JSON based syntax which can control the full range of features but is only authored by technical users.

So the answer to your question is largely dependent on who is authoring the rules.

---

_[View the full topic](https://discuss.elastic.co/t/elastic-lucene-vs-kql-vs-dsl-vs-eql/302588)._
