Event Query Language (EQL): Detections in space and time

United States and Canada Virtual

Thursday, January 21, 2021, 2:00 – 3:00 AM UTC


About this event

Elastic has added a new query language to the stack designed to make it easier to see the flow of events and provide detection. EQL was originally developed by Endgame and now is part of the Stack after joining forces with Elastic. EQL provides us with a unique ability to look across our data in both the context of its time series flow, and the relationship between the events that lead to a positive detection. Join us as we explore this new powerful tool and how it gives every user a new edge.