# Kibana Query Language documentation

**URL:** <https://discuss.elastic.co/t/kibana-query-language-documentation/213178>\
**Category:** Kibana\
**Created:** [December 27, 2019, 10:46am UTC](https://discuss.elastic.co/t/kibana-query-language-documentation/213178 "2019-12-27T10:46:40Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [December 27, 2019, 11:23am UTC](https://discuss.elastic.co/t/kibana-query-language-documentation/213178/2 "2019-12-27T11:23:44Z")

</div>

Where is your log data coming from? A good reference may be from the vendor providing the log data.

Is your log data in Elastic Common Schema (ECS)? Here is a link to ECS docs that define some of the fields you are asking about [ECS Field Reference | Elastic Common Schema (ECS) Reference [8.11] | Elastic](https://www.elastic.co/guide/en/ecs/current/ecs-field-reference.html)

agent: [Agent Fields | Elastic Common Schema (ECS) Reference [8.11] | Elastic](https://www.elastic.co/guide/en/ecs/current/ecs-agent.html)

host: [Host Fields | Elastic Common Schema (ECS) Reference [8.11] | Elastic](https://www.elastic.co/guide/en/ecs/current/ecs-host.html)

 ![Screen Shot 2019-12-27 at 4.09.35 AM](https://us1.discourse-cdn.com/elastic/original/3X/b/a/baa9129a8b1122a8c785df3210ba5d805d26ac2e.png)

As for `@timestamp`, checkout out [What is the difference between @timestamp and timestamp?](https://discuss.elastic.co/t/what-is-the-difference-between-timestamp-and-timestamp/46464)

> @ fields are usually ones generated by Logstash as metadata ones, @timestamp being the value that the event was processed by Logstash.

Set `@timestamp` as the `Time Filter field name ` when setting up your [Kibana index pattern](https://www.elastic.co/guide/en/kibana/current/index-patterns.html). This will allow Kibana's timepicker to filter on `@timestamp` field.

---

_[View the full topic](https://discuss.elastic.co/t/kibana-query-language-documentation/213178)._
