# Refer to value lists in ES|QL?

**URL:** <https://discuss.elastic.co/t/refer-to-value-lists-in-es-ql/384135>\
**Category:** SIEM\
**Tags:** esql\
**Created:** [December 17, 2025, 8:16am UTC](https://discuss.elastic.co/t/refer-to-value-lists-in-es-ql/384135 "2025-12-17T08:16:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![alyx](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@alyx](https://discuss.elastic.co/u/alyx)\
**Post date:** [December 17, 2025, 8:16am UTC](https://discuss.elastic.co/t/refer-to-value-lists-in-es-ql/384135/1 "2025-12-17T08:16:28Z")

</div>

Hi everyone!

Trying to migrate from other SIEM platforms. One question is, is it possible to define some lists and refer to them across different rules? Like `WHERE source.ip IN ${some_defined_list}`?

I tried to use [value list](https://www.elastic.co/docs/solutions/security/detect-and-alert/create-manage-value-lists) for rule exceptions and yes it worked, but I want to directly use value list in the query for more complex logics. Should I use other kinds of rules like KQL, EQL, etc.? I’m a bit confused when seeing so many query languages in Elastic…

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2026, 8:17am UTC](https://discuss.elastic.co/t/refer-to-value-lists-in-es-ql/384135/2 "2026-01-14T08:17:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![mouhc1ne](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mouhc1ne/32/144573_2.png) [@mouhc1ne](https://discuss.elastic.co/u/mouhc1ne)\
**Post date:** [April 17, 2026, 6:37pm UTC](https://discuss.elastic.co/t/refer-to-value-lists-in-es-ql/384135/3 "2026-04-17T18:37:21Z")

</div>

Hi @alyx !

So you want the ability to check if an IP belongs to a pre-determined list of IPs that is populated somewhere somehow and you wanna do that directly in ESQL?

Are you able to have those IPs dumped to a field in an index? If yes, then one possible way to achieve this is to use a combination of [VALUES](https://www.elastic.co/docs/reference/query-languages/esql/functions-operators/aggregation-functions/values) and [MV\_CONTAINS](https://www.elastic.co/docs/reference/query-languages/esql/functions-operators/mv-functions/mv_contains). Both functions support the `IP` type.

**Example.**  
Assuming `some_index` has column `ip` of type `IP`.

```auto
FROM some_index

# dedupes the passed field into a single multi-valued list
| STATS ips = VALUES(ip)

# true if-and-only-if every element in the subset (second param) belongs to the superset (first param)
# pass any number of IPs in the subset
| EVAL found = MV_CONTAINS(ips, [some_ip_1, some_ip2, ...])

```
