# Timespan without a sequence

**URL:** <https://discuss.elastic.co/t/timespan-without-a-sequence/276370>\
**Category:** Elastic Security\
**Tags:** eql-elastic-query-language\
**Created:** [June 18, 2021, 10:11am UTC](https://discuss.elastic.co/t/timespan-without-a-sequence/276370 "2021-06-18T10:11:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ima](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ima/32/99895_2.png) [@ima](https://discuss.elastic.co/u/ima)\
**Post date:** [June 18, 2021, 10:11am UTC](https://discuss.elastic.co/t/timespan-without-a-sequence/276370/1 "2021-06-18T10:11:11Z")

</div>

hello guys, is there any other way to define a timespan without using sequence in eql rules creation

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [June 24, 2021, 11:41pm UTC](https://discuss.elastic.co/t/timespan-without-a-sequence/276370/2 "2021-06-24T23:41:20Z")

</div>

Hey there @ima! 👋

So you can also use the [ES Query DSL](https://www.elastic.co/guide/en/elasticsearch/reference/current/eql.html#eql-search-filter-query-dsl) to constrain by time.

e.g.

```auto
GET /my-data-stream/_eql/search
{
  "filter": {
    "range": {
      "@timestamp": {
        "gte": "now-1d/d",
        "lt": "now/d"
      }
    }
  },
  "query": """
    file where (file.type == "file" and file.name == "cmd.exe")
  """
}

```

If this isn't exactly what you're looking for, could you provide a little more detail into the type of EQL query you're trying to write?

Cheers!  
Garrrett

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 22, 2021, 11:41pm UTC](https://discuss.elastic.co/t/timespan-without-a-sequence/276370/3 "2021-07-22T23:41:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
