# ES|QL query all types of logs

**URL:** <https://discuss.elastic.co/t/es-ql-query-all-types-of-logs/377086>\
**Category:** Logs\
**Created:** [April 14, 2025, 3:40am UTC](https://discuss.elastic.co/t/es-ql-query-all-types-of-logs/377086 "2025-04-14T03:40:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![michael005](https://avatars.discourse-cdn.com/v4/letter/m/898d66/32.png) [@michael005](https://discuss.elastic.co/u/michael005)\
**Post date:** [April 14, 2025, 3:40am UTC](https://discuss.elastic.co/t/es-ql-query-all-types-of-logs/377086/1 "2025-04-14T03:40:47Z")

</div>

Hello- I hope this is the right channel for my ES|QL question. I've setup a centralized log server with 3 IPs sending their logs to that server. I've installed an agent, but now can't figure out the right query to list every type of log coming from each of the 3 IPs. Is this type of query possible?

I'm transitioning away from Splunk, but query examples for ELK aren't as available as Splunk. Any resources, links or query suggestions are appreciated!

---

<div class="post-metadata">

**Author:** ![Yngrid\_Coello](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yngrid_coello/32/146443_2.png) [@Yngrid\_Coello](https://discuss.elastic.co/u/Yngrid_Coello)\
**Post date:** [April 14, 2025, 9:32am UTC](https://discuss.elastic.co/t/es-ql-query-all-types-of-logs/377086/2 "2025-04-14T09:32:37Z")

</div>

Hey @michael005,  
in which field are you storing the ip? in which field are you storing the type of log?  
From the top of my head I can think of something like

```auto
FROM logs-*
| EVAL source_ip = your_ip_field
| EVAL log_type = your_log_type_field
| STATS doc_count = COUNT(*) BY source_ip, log_type
| SORT source_ip, doc_count DESC

```

As for sources where to check out ES|QL information, you could start with [official documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/esql.html) where you will find some information about the functions available and some examples.

Let me know if I can help you further.

---

<div class="post-metadata">

**Author:** ![michael005](https://avatars.discourse-cdn.com/v4/letter/m/898d66/32.png) [@michael005](https://discuss.elastic.co/u/michael005)\
**Post date:** [April 16, 2025, 4:33am UTC](https://discuss.elastic.co/t/es-ql-query-all-types-of-logs/377086/3 "2025-04-16T04:33:34Z")

</div>

@Yngrid_Coello - Thanks for that query! That was different from what I was imagining (coming from a Splunk point of view).
