Timespan without a sequence

hello guys, is there any other way to define a timespan without using sequence in eql rules creation

Hey there @ima! :wave:

So you can also use the ES Query DSL to constrain by time.

e.g.

GET /my-data-stream/_eql/search
{
  "filter": {
    "range": {
      "@timestamp": {
        "gte": "now-1d/d",
        "lt": "now/d"
      }
    }
  },
  "query": """
    file where (file.type == "file" and file.name == "cmd.exe")
  """
}

If this isn't exactly what you're looking for, could you provide a little more detail into the type of EQL query you're trying to write?

Cheers!
Garrrett