# KQL Comprehensive Tutorial on Event Correlation Rules

**URL:** <https://discuss.elastic.co/t/kql-comprehensive-tutorial-on-event-correlation-rules/318669>\
**Category:** SIEM\
**Tags:** docker\
**Created:** [November 10, 2022, 3:34pm UTC](https://discuss.elastic.co/t/kql-comprehensive-tutorial-on-event-correlation-rules/318669 "2022-11-10T15:34:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ElasticUser11](https://avatars.discourse-cdn.com/v4/letter/e/ee59a6/32.png) [@ElasticUser11](https://discuss.elastic.co/u/ElasticUser11)\
**Post date:** [November 10, 2022, 3:34pm UTC](https://discuss.elastic.co/t/kql-comprehensive-tutorial-on-event-correlation-rules/318669/1 "2022-11-10T15:34:59Z")

</div>

I need to build some rather complex rules, but I'm just getting started with KQL. I haven't found any in-depth comprehensive tuts out there on event correlation. Everything is always brief and basic. Anyone know of any good resource?

Thanks for chiming in!

---

<div class="post-metadata">

**Author:** ![wsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wsouza/32/92547_2.png) [@wsouza](https://discuss.elastic.co/u/wsouza)\
**Post date:** [November 12, 2022, 10:45pm UTC](https://discuss.elastic.co/t/kql-comprehensive-tutorial-on-event-correlation-rules/318669/2 "2022-11-12T22:45:30Z")

</div>

You can use EQL [EQL syntax reference | Elasticsearch Guide [8.5] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/eql-syntax.html) for event mapping. Take a look at these links:

- [https://www.elastic.co/en/security-labs/handy-elastic-tools-for-the-enthusiastic-detection-engineer](https://www.elastic.co/en/security-labs/handy-elastic-tools-for-the-enthusiastic-detection-engineer)

- [https://www.threatbear.co/detecting-cve-2021-41379-using-eql-2ec67a644b25](https://www.threatbear.co/detecting-cve-2021-41379-using-eql-2ec67a644b25)

- [EQL search in Elastic SIEM Detection rules](https://www.linkedin.com/pulse/eql-search-elastic-siem-detection-rules-alessandro-brofferio/)

- [Event Query Language (EQL): Detections in space and time - YouTube](https://www.youtube.com/watch?v=C-Kxzj-Dw_U)

---

<div class="post-metadata">

**Author:** ![ElasticUser11](https://avatars.discourse-cdn.com/v4/letter/e/ee59a6/32.png) [@ElasticUser11](https://discuss.elastic.co/u/ElasticUser11)\
**Post date:** [November 14, 2022, 5:44pm UTC](https://discuss.elastic.co/t/kql-comprehensive-tutorial-on-event-correlation-rules/318669/3 "2022-11-14T17:44:01Z")

</div>

Thank you! That was really helpful!

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [November 28, 2022, 8:05pm UTC](https://discuss.elastic.co/t/kql-comprehensive-tutorial-on-event-correlation-rules/318669/4 "2022-11-28T20:05:13Z")

</div>

Fyi [https://www.elastic.co/en/security-labs/handy-elastic-tools-for-the-enthusiastic-detection-engineer](https://www.elastic.co/en/security-labs/handy-elastic-tools-for-the-enthusiastic-detection-engineer)

gives me a 404

Guessing you mean

> **[Handy Elastic Tools for the Enthusiastic Detection Engineer](https://www.elastic.co/security-labs/handy-elastic-tools-for-the-enthusiastic-detection-engineer)**
>
> Tools like the EQLPlaygound, RTAs, and detection-rules CLI are great resources for getting started with EQL, threat hunting, and detection engineering respectively.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2022, 8:05pm UTC](https://discuss.elastic.co/t/kql-comprehensive-tutorial-on-event-correlation-rules/318669/5 "2022-12-26T20:05:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
