# EQL: Why basic query is different from dataset

**URL:** <https://discuss.elastic.co/t/eql-why-basic-query-is-different-from-dataset/252242>\
**Category:** SIEM\
**Created:** [October 15, 2020, 4:58pm UTC](https://discuss.elastic.co/t/eql-why-basic-query-is-different-from-dataset/252242 "2020-10-15T16:58:21Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [October 15, 2020, 4:58pm UTC](https://discuss.elastic.co/t/eql-why-basic-query-is-different-from-dataset/252242/1 "2020-10-15T16:58:21Z")

</div>

I'm running a simple EQL query to test as follows, but NOT reporting anything back

```auto
GET winlogbeat*/_eql/search
{
  "query": """
  process where process.name == "services.exe"
  """
}

```

Quite lot of data is present and If I run an sql query to see the data it is present.

```auto
POST /_sql?format=txt
{
  "query": """
  SELECT "process.name", "event.category", count(*) FROM "winlogbeat*"
  WHERE "process.name" = 'services.exe'
  GROUP BY "process.name","event.category"
  """
} 

```

```auto
 process.name |event.category | count(*)    
---------------+---------------+---------------
services.exe |authentication |3607           
services.exe |process |39             

```

Any idea if I need to something else to setup EQL?

---

<div class="post-metadata">

**Author:** ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)\
**Post date:** [October 15, 2020, 5:59pm UTC](https://discuss.elastic.co/t/eql-why-basic-query-is-different-from-dataset/252242/2 "2020-10-15T17:59:32Z")

</div>

Hi @kelk! Thanks for checking out EQL! Let's see if we can get you squared away here...

The [two concepts required for EQL to work](https://www.elastic.co/guide/en/elasticsearch/reference/master/eql.html#eql-required-fields) are _category_ and _time_, which by default correspond to the `event.category` and `@timestamp` fields, respectively.

If your mappings are correct but your documents are missing either of these fields, the search will succeed but with no results. Since you didn't mention an error, I suspect that you're missing a timestamp field.

If your documents _do_ have a timestamp field but it's not named `@timestamp`, you can [specify that as part of the query](https://www.elastic.co/guide/en/elasticsearch/reference/master/eql.html#specify-a-timestamp-or-event-category-field) rather than adding/updating your documents.

I hope that helps! But if it doesn't, sharing your winlogbeat mappings along with a few representative documents and the EQL responses/errors will help to further diagnose. Cheers!

---

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [October 15, 2020, 7:59pm UTC](https://discuss.elastic.co/t/eql-why-basic-query-is-different-from-dataset/252242/3 "2020-10-15T19:59:25Z")

</div>

There was no error, but just gives empty result

```auto
{
  "is_partial" : false,
  "is_running" : false,
  "took" : 0,
  "timed_out" : false,
  "hits" : {
    "total" : {
      "value" : 0,
      "relation" : "eq"
    },
    "events" : []
  }
}

```

btw the data comes from WinLogBeats and is parsed in ECS format too. event.category & @timestamp is present etc.

---

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [October 15, 2020, 8:01pm UTC](https://discuss.elastic.co/t/eql-why-basic-query-is-different-from-dataset/252242/4 "2020-10-15T20:01:42Z")

</div>

Strange. It worked when I put the actual index, but if I give a index\* (wildcard), it fails which is a shame.

```auto
GET winlogbeat-7.9.2-2020.10.12-000001/_eql/search
{
  "query": """
  process where process.name == "services.exe"
  """
}

```

works !! expected it to be work with wildcard. Can you please put this as a feature?

---

<div class="post-metadata">

**Author:** ![RylandHerrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rylandherrick/32/67401_2.png) [@RylandHerrick](https://discuss.elastic.co/u/RylandHerrick)\
**Post date:** [October 15, 2020, 8:38pm UTC](https://discuss.elastic.co/t/eql-why-basic-query-is-different-from-dataset/252242/5 "2020-10-15T20:38:42Z")

</div>

@kelk glad you were able to get things working to a degree!

It's possible that there are mapping differences across your winlogbeat indexes; you might be able to narrow that down by starting with your concrete index, and then loosening the wildcard (`winlogbeat-7.9.2-2020.10.12*`, `winlogbeat-7.9.2-2020.10*`, etc) until you see the failure.

We also made [an improvement](https://github.com/elastic/elasticsearch/pull/63192) or [two](https://github.com/elastic/elasticsearch/pull/63573) to EQL's index resolution for 7.10, so that behavior will be improved soon!

---

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [October 15, 2020, 9:14pm UTC](https://discuss.elastic.co/t/eql-why-basic-query-is-different-from-dataset/252242/6 "2020-10-15T21:14:45Z")

</div>

thank you again.  
I feel EQL have so much legs and is much simpler for aggregation/pipe/siem/event-stitch together. may be if you can develop it to the likes of Splunk SPL or similar, it would become the most important language within ELK framework

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2020, 9:14pm UTC](https://discuss.elastic.co/t/eql-why-basic-query-is-different-from-dataset/252242/7 "2020-11-12T21:14:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
