Event Query Language (EQL): Detections in space and time

United States and Canada Virtual

Jan 21, 2021, 2:00 – 3:00 AM


About this event

Elastic has added a new query language to the stack designed to make it easier to see the flow of events and provide detection. EQL was originally developed by Endgame and now is part of the Stack after joining forces with Elastic. EQL provides us with a unique ability to look across our data in both the context of its time series flow, and the relationship between the events that lead to a positive detection. Join us as we explore this new powerful tool and how it gives every user a new edge.


  • Olivia Petrie


Contact Us