Skip to content

Eql Sampling#85206

Merged
astefan merged 20 commits intoelastic:feature/eql_samplesfrom
astefan:sampling_in_eql
May 30, 2022
Merged

Eql Sampling#85206
astefan merged 20 commits intoelastic:feature/eql_samplesfrom
astefan:sampling_in_eql

Conversation

@astefan
Copy link
Copy Markdown
Contributor

@astefan astefan commented Mar 22, 2022

A sample searches for events matching the declared filters in all possible permutations. The result of a sample is identical in structure with the one of a sequence, but for each combination of join key values, if there is at least one match, the result will contain only one events combination matching the sample (as opposed to sequences where all results are returned).

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

:Analytics/EQL EQL querying >feature Team:QL (Deprecated) Meta label for query languages team v8.4.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants