esql-security-solution.asciidoc 1.3 KB

123456789101112131415161718192021222324252627282930313233343536
  1. [[esql-elastic-security]]
  2. === Using {esql} in {elastic-sec}
  3. ++++
  4. <titleabbrev>Using {esql} in {elastic-sec}</titleabbrev>
  5. ++++
  6. You can use {esql} in {elastic-sec} to investigate events in Timeline and create
  7. detection rules. Use the Elastic AI Assistant to build {esql} queries, or answer
  8. questions about the {esql} query language.
  9. [discrete]
  10. [[esql-elastic-security-timeline]]
  11. === Use {esql} to investigate events in Timeline
  12. You can use {esql} in Timeline to filter, transform, and analyze event data
  13. stored in {es}. To start using {esql}, open the **{esql}** tab. To learn
  14. more, refer to {security-guide}/timelines-ui.html#esql-in-timeline[Investigate
  15. events in Timeline].
  16. [discrete]
  17. [[esql-elastic-security-detection-rules]]
  18. === Use {esql} to create detection rules
  19. Use the {esql} rule type to create detection rules using {esql} queries. The
  20. {esql} rule type supports aggregating and non-aggregating queries. To learn
  21. more, refer to {security-guide}/rules-ui-create.html#create-esql-rule[Create an
  22. {esql} rule].
  23. [discrete]
  24. [[esql-elastic-security-ai-assistant]]
  25. === Elastic AI Assistant
  26. Use the Elastic AI Assistant to build {esql} queries, or answer questions about
  27. the {esql} query language. To learn more, refer to
  28. {security-guide}/security-assistant.html[AI Assistant].