# KQL in ES query?

**URL:** <https://discuss.elastic.co/t/kql-in-es-query/227407>\
**Category:** Elasticsearch\
**Created:** [April 9, 2020, 9:03pm UTC](https://discuss.elastic.co/t/kql-in-es-query/227407 "2020-04-09T21:03:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![cyberzlo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberzlo/32/65490_2.png) [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Post date:** [April 9, 2020, 9:03pm UTC](https://discuss.elastic.co/t/kql-in-es-query/227407/1 "2020-04-09T21:03:55Z")

</div>

Hi, is possible to use KQL in ES query?

My problem is that I have just basic license, no alerts, and this is my personal project so no option to buy better license. I can do PHP/Bash script but problem is about query… KQL and doing some searchers in Kibana is nice and easy, but looks like curl for ES use diffrent query.

How deal with that? Can I somehow do query using crontab every 10 minutes to query ES for last 10 minutes? Best would be using created discovery queries in Kibana, if will return something for last 10 minutes I can deal with it in script. It is possible to curl ES for such disovery query from Kibana or something that will easy solve such problem?🙂

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [April 9, 2020, 11:53pm UTC](https://discuss.elastic.co/t/kql-in-es-query/227407/2 "2020-04-09T23:53:37Z")

</div>

Hello @cyberzlo

At the moment the [KQL language is only processed by Kibana](https://www.elastic.co/guide/en/kibana/current/kuery-query.html).

I might suggest some options:

- Use the [Lucene query string query](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html#query-dsl-query-string-query). It is quite similar to KQL.

```auto
GET /_search
{
  "query": {
      "query_string" : {
          "query" : "city:((new york city) OR (big apple))",
          "default_field" : "*"
      }
  }
}

```

- Use the [Simple query string query](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-simple-query-string-query.html). Its syntax is more limited than the Lucene query string query and it does not return errors for invalid syntax. Instead, it ignores any invalid parts of the query string.

```auto
GET /_search
{
  "query": {
    "simple_query_string" : {
      "query": "\"fried eggs\" +(eggplant | potato) -frittata",
      "fields": ["title^5", "body"],
      "default_operator": "and"
    }
  }
}

```

- Use the [Elasticsearch SQL CLI](https://www.elastic.co/guide/en/elasticsearch/reference/current/sql-cli.html)  
It allows to write an SQL Query and return data in JSON, CSV, TEXT format

```auto
./bin/elasticsearch-sql-cli ...

```

- Use the [Elasticsearch SQL API](https://www.elastic.co/guide/en/elasticsearch/reference/current/sql-rest.html) with `curl` or any `http` client. You'll need to take care of the pagination in case the query returns more than one page.  
It allows to write an SQL Query and return data in JSON, CSV, TEXT format

```auto
POST /_sql?format=txt
{
    "query": "SELECT * FROM library ORDER BY page_count DESC LIMIT 5"
}

```

- We also offer an official [PHP Elasticsearch client](https://www.elastic.co/guide/en/elasticsearch/client/php-api/current/index.html)

The SQL solutions require at least a Basic license.

---

<div class="post-metadata">

**Author:** ![cyberzlo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberzlo/32/65490_2.png) [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Post date:** [April 10, 2020, 9:53am UTC](https://discuss.elastic.co/t/kql-in-es-query/227407/3 "2020-04-10T09:53:42Z")

</div>

Hmm, but this SQL functions are in X-PACK, and I have this free basic license, so can I use it or not? I thought that if something is in X-PACK it is paid.

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [April 10, 2020, 10:16am UTC](https://discuss.elastic.co/t/kql-in-es-query/227407/4 "2020-04-10T10:16:29Z")

</div>

Hello @cyberzlo

> [@cyberzlo](#):
>
> Hmm, but this SQL functions are in X-PACK, and I have this free basic license, so can I use it or not? I thought that if something is in X-PACK it is paid.

This is the [table of features with the licensing types](https://www.elastic.co/subscriptions).

Under the `basic` license (free), you have a lot of features (not listed here), including:

- Elasticsearch SQL APIs & CLI
- Full stack monitoring
- ILM, Rollups, Transforms, SLM
- Security (native, file RBAC, TLS, API Keys, Kibana spaces & feature control)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2020, 10:16am UTC](https://discuss.elastic.co/t/kql-in-es-query/227407/5 "2020-05-08T10:16:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
