Event Query Language (EQL) Logo

Event Query Language (EQL)

0
Free
1 saves
Updated 11 March 2025
Visit Website

Browse a library of EQL analytics now natively integrated in Elasticsearch since Endgame joined forces with Elastic. EQL in Elasticsearch accommodates non-security users with changes summarized in the Elasticsearch EQL documentation. Get started by installing the EQL module with Python 2.7 and 3.5+, then try a sample json file and test it with EQL commands.

FEATURES

SIMILAR TOOLS

Python library and command line tools for log visualization with interactive plots.

Free

A service that analyzes and visualizes security data to investigate potential security issues.

Free

A tool collection for filtering and visualizing logon events, designed for experienced DFIR specialists in threat hunting and incident response.

Free

Converts Sigma and Yara rules to CRYPTTECH's SIEM query language.

Free

Open source security data lake for AWS with real-time log normalization and Detection-as-Code capabilities.

Free

Sysdig is a system visibility tool with native container support.

Free

A collection of free shareable log samples from various systems with evidence of compromise and malicious activity, maintained by Dr. Anton Chuvakin.

Free

A method for log volume reduction without losing analytical capability.

Free

SysmonSearch makes event log analysis more effective by aggregating Microsoft Sysmon logs and providing detailed analysis through Elasticsearch and Kibana.

Free
CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

VAT: NL005301434B12

Copyright © 2025 - All rights reserved