# ES|QL Search if a value in a list is in another list

**URL:** <https://discuss.elastic.co/t/es-ql-search-if-a-value-in-a-list-is-in-another-list/370784>\
**Category:** Kibana\
**Tags:** esql\
**Created:** [November 19, 2024, 5:39pm UTC](https://discuss.elastic.co/t/es-ql-search-if-a-value-in-a-list-is-in-another-list/370784 "2024-11-19T17:39:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![isugg](https://avatars.discourse-cdn.com/v4/letter/i/8797f3/32.png) [@isugg](https://discuss.elastic.co/u/isugg)\
**Post date:** [November 19, 2024, 5:39pm UTC](https://discuss.elastic.co/t/es-ql-search-if-a-value-in-a-list-is-in-another-list/370784/1 "2024-11-19T17:39:26Z")

</div>

Trying to find all instances of "-a" or "-x" in process arguments, from endpoint logs. I have the following values:

process.name: "process"  
process.command\_line: "process -a -b -c"  
process.args: ["process", "-a", "-b" "-c"]

process.name: "process"  
process.command\_line: "process -x -b -c"  
process.args: ["process", "-x", "-b" "-c"]

The following query returns what I would expect:

from logs-\*endpoint\*  
| where process.command\_line LIKE "\*-a\*" OR process.command\_line LIKE "\*-x\*"

This query returns nothing.

from logs-\*endpoint\*  
| where process.args IN ("-a", "-x") //returns nothing

How do I query for values that are stored as a list, if they belong to another list?

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [November 20, 2024, 7:10am UTC](https://discuss.elastic.co/t/es-ql-search-if-a-value-in-a-list-is-in-another-list/370784/2 "2024-11-20T07:10:44Z")

</div>

> from logs-_endpoint_  
> | where process.args IN ("-a", "-x") //returns nothing

I believe `IN` expects a single element on the left side and doesn't work in that way.

My ES|QL knowledge is still growing. I did find a way to do this but it's a bit messy.

```auto
FROM logs-* | 
eval values = ["start","connection"] |
WHERE MV_COUNT(MV_DEDUPE(MV_APPEND(event.type, values))) < (MV_DEDUPE(MV_COUNT(event.type)) + MV_COUNT(values)) |
LIMIT 1000

```

Essentially `values` is set to the values you want to check for and then I used  
`WHERE MV_COUNT(MV_DEDUPE(MV_APPEND(event.type, values))) < (MV_COUNT(event.type) + MV_COUNT(values)) `

With `MV_COUNT(MV_DEDUPE(MV_APPEND(event.type, values)))` being used to join the two lists, remove duplicates, and then take a count, and  
`(MV_COUNT(MV_DEDUPE(event.type)) + MV_COUNT(values))` being used to join the two lists, keep duplicates, and then take a count.

If these two numbers aren't the same, it means there was a duplicate across the two lists, that is that at least one of the items in `values` was in `event.type`.

Hopefully there's an easier way to do this and someone will come along with a better suggestion!

---

<div class="post-metadata">

**Author:** ![isugg](https://avatars.discourse-cdn.com/v4/letter/i/8797f3/32.png) [@isugg](https://discuss.elastic.co/u/isugg)\
**Post date:** [November 21, 2024, 2:23pm UTC](https://discuss.elastic.co/t/es-ql-search-if-a-value-in-a-list-is-in-another-list/370784/3 "2024-11-21T14:23:48Z")

</div>

Hello Strawgate, I will let you know how this works when our stack gets updated to 8.16 and includes MV\_APPEND(). This solution seems clever though, and I appreciate the help. I assume this will have better runtimes than the expensive process.command\_line LIKE "\*something\*" operation.
