\documentclass[10pt,a4paper]{article} % Packages \usepackage{fancyhdr} % For header and footer \usepackage{multicol} % Allows multicols in tables \usepackage{tabularx} % Intelligent column widths \usepackage{tabulary} % Used in header and footer \usepackage{hhline} % Border under tables \usepackage{graphicx} % For images \usepackage{xcolor} % For hex colours %\usepackage[utf8x]{inputenc} % For unicode character support \usepackage[T1]{fontenc} % Without this we get weird character replacements \usepackage{colortbl} % For coloured tables \usepackage{setspace} % For line height \usepackage{lastpage} % Needed for total page number \usepackage{seqsplit} % Splits long words. %\usepackage{opensans} % Can't make this work so far. Shame. Would be lovely. \usepackage[normalem]{ulem} % For underlining links % Most of the following are not required for the majority % of cheat sheets but are needed for some symbol support. \usepackage{amsmath} % Symbols \usepackage{MnSymbol} % Symbols \usepackage{wasysym} % Symbols %\usepackage[english,german,french,spanish,italian]{babel} % Languages % Document Info \author{Sujit Ghosal (thesujit)} \pdfinfo{ /Title (kibana-query-language-kql.pdf) /Creator (Cheatography) /Author (Sujit Ghosal (thesujit)) /Subject (Kibana Query Language (KQL) Cheat Sheet) } % Lengths and widths \addtolength{\textwidth}{6cm} \addtolength{\textheight}{-1cm} \addtolength{\hoffset}{-3cm} \addtolength{\voffset}{-2cm} \setlength{\tabcolsep}{0.2cm} % Space between columns \setlength{\headsep}{-12pt} % Reduce space between header and content \setlength{\headheight}{85pt} % If less, LaTeX automatically increases it \renewcommand{\footrulewidth}{0pt} % Remove footer line \renewcommand{\headrulewidth}{0pt} % Remove header line \renewcommand{\seqinsert}{\ifmmode\allowbreak\else\-\fi} % Hyphens in seqsplit % This two commands together give roughly % the right line height in the tables \renewcommand{\arraystretch}{1.3} \onehalfspacing % Commands \newcommand{\SetRowColor}[1]{\noalign{\gdef\RowColorName{#1}}\rowcolor{\RowColorName}} % Shortcut for row colour \newcommand{\mymulticolumn}[3]{\multicolumn{#1}{>{\columncolor{\RowColorName}}#2}{#3}} % For coloured multi-cols \newcolumntype{x}[1]{>{\raggedright}p{#1}} % New column types for ragged-right paragraph columns \newcommand{\tn}{\tabularnewline} % Required as custom column type in use % Font and Colours \definecolor{HeadBackground}{HTML}{333333} \definecolor{FootBackground}{HTML}{666666} \definecolor{TextColor}{HTML}{333333} \definecolor{DarkBackground}{HTML}{16A085} \definecolor{LightBackground}{HTML}{F0F9F7} \renewcommand{\familydefault}{\sfdefault} \color{TextColor} % Header and Footer \pagestyle{fancy} \fancyhead{} % Set header to blank \fancyfoot{} % Set footer to blank \fancyhead[L]{ \noindent \begin{multicols}{3} \begin{tabulary}{5.8cm}{C} \SetRowColor{DarkBackground} \vspace{-7pt} {\parbox{\dimexpr\textwidth-2\fboxsep\relax}{\noindent \hspace*{-6pt}\includegraphics[width=5.8cm]{/web/www.cheatography.com/public/images/cheatography_logo.pdf}} } \end{tabulary} \columnbreak \begin{tabulary}{11cm}{L} \vspace{-2pt}\large{\bf{\textcolor{DarkBackground}{\textrm{Kibana Query Language (KQL) Cheat Sheet}}}} \\ \normalsize{by \textcolor{DarkBackground}{Sujit Ghosal (thesujit)} via \textcolor{DarkBackground}{\uline{cheatography.com/210137/cs/45326/}}} \end{tabulary} \end{multicols}} \fancyfoot[L]{ \footnotesize \noindent \begin{multicols}{3} \begin{tabulary}{5.8cm}{LL} \SetRowColor{FootBackground} \mymulticolumn{2}{p{5.377cm}}{\bf\textcolor{white}{Cheatographer}} \\ \vspace{-2pt}Sujit Ghosal (thesujit) \\ \uline{cheatography.com/thesujit} \\ \end{tabulary} \vfill \columnbreak \begin{tabulary}{5.8cm}{L} \SetRowColor{FootBackground} \mymulticolumn{1}{p{5.377cm}}{\bf\textcolor{white}{Cheat Sheet}} \\ \vspace{-2pt}Not Yet Published.\\ Updated 24th December, 2024.\\ Page {\thepage} of \pageref{LastPage}. \end{tabulary} \vfill \columnbreak \begin{tabulary}{5.8cm}{L} \SetRowColor{FootBackground} \mymulticolumn{1}{p{5.377cm}}{\bf\textcolor{white}{Sponsor}} \\ \SetRowColor{white} \vspace{-5pt} %\includegraphics[width=48px,height=48px]{dave.jpeg} Measure your website readability!\\ www.readability-score.com \end{tabulary} \end{multicols}} \begin{document} \raggedright \raggedcolumns % Set font size to small. Switch to any value % from this page to resize cheat sheet text: % www.emerson.emory.edu/services/latex/latex_169.html \footnotesize % Small font. \begin{multicols*}{2} \begin{tabularx}{8.4cm}{x{2.052 cm} x{2.128 cm} x{3.42 cm} } \SetRowColor{DarkBackground} \mymulticolumn{3}{x{8.4cm}}{\bf\textcolor{white}{Basic Queries}} \tn % Row 0 \SetRowColor{LightBackground} \{\{bb\}\}{\bf{SYNTAX}} & \{\{bb\}\}{\bf{DESC}} & \{\{bb\}\}{\bf{EXAMPLE}} \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} Simple term & Search any field & {\emph{error}} \tn % Row Count 4 (+ 2) % Row 2 \SetRowColor{LightBackground} Field value & Match exact field & {\emph{status:200}} \tn % Row Count 6 (+ 2) % Row 3 \SetRowColor{white} Phrase & Match exact text & {\emph{message:"disk full"}} \tn % Row Count 8 (+ 2) % Row 4 \SetRowColor{LightBackground} Field exists & Has any value & {\emph{status:}}* \tn % Row Count 10 (+ 2) % Row 5 \SetRowColor{white} Nested & Dot notation & {\emph{kubernetes.pod.name:nginx}} \tn % Row Count 12 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}---} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{1.976 cm} x{1.748 cm} x{3.876 cm} } \SetRowColor{DarkBackground} \mymulticolumn{3}{x{8.4cm}}{\bf\textcolor{white}{Comparisons}} \tn % Row 0 \SetRowColor{LightBackground} \{\{bb\}\}{\bf{SYNTAX}} & \{\{bb\}\}{\bf{DESC}} & \{\{bb\}\}{\bf{EXAMPLE}} \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} \textgreater{} & Greater than & {\emph{bytes \textgreater{} 1000}} \tn % Row Count 4 (+ 2) % Row 2 \SetRowColor{LightBackground} \textless{} & Less than & {\emph{status \textless{} 500}} \tn % Row Count 5 (+ 1) % Row 3 \SetRowColor{white} \textgreater{}= & \seqsplit{Greater/equal} & {\emph{@timestamp \textgreater{}= "2023-01-01"}} \tn % Row Count 7 (+ 2) % Row 4 \SetRowColor{LightBackground} \textless{}= & \seqsplit{Less/equal} & {\emph{response.time \textless{}= "2024-01-01"}} \tn % Row Count 9 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}---} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{2.584 cm} x{2.28 cm} x{2.736 cm} } \SetRowColor{DarkBackground} \mymulticolumn{3}{x{8.4cm}}{\bf\textcolor{white}{Wildcards}} \tn % Row 0 \SetRowColor{LightBackground} \{\{bb\}\}{\bf{SYNTAX}} & \{\{bb\}\}{\bf{DESC}} & \{\{bb\}\}{\bf{EXAMPLE}} \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} * & Many chars & {\emph{user}}name* \tn % Row Count 3 (+ 1) % Row 2 \SetRowColor{LightBackground} ? & One char & {\emph{user?name}} \tn % Row Count 4 (+ 1) % Row 3 \SetRowColor{white} Prefix & Starts with & {\emph{error}}* \tn % Row Count 5 (+ 1) % Row 4 \SetRowColor{LightBackground} Contains & Inside text & {\emph{*error*}} \tn % Row Count 6 (+ 1) % Row 5 \SetRowColor{white} Suffix & Ends with & {\emph{*.com}} \tn % Row Count 7 (+ 1) \hhline{>{\arrayrulecolor{DarkBackground}}---} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{2.128 cm} x{2.204 cm} x{3.268 cm} } \SetRowColor{DarkBackground} \mymulticolumn{3}{x{8.4cm}}{\bf\textcolor{white}{Arrays}} \tn % Row 0 \SetRowColor{LightBackground} \{\{bb\}\}{\bf{SYNTAX}} & \{\{bb\}\}{\bf{DESC}} & \{\{bb\}\}{\bf{EXAMPLE}} \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} Any match & Match array value & {\emph{tags:(error or warning)}} \tn % Row Count 4 (+ 2) % Row 2 \SetRowColor{LightBackground} All match & All must match & {\emph{tags:(error and info)}} \tn % Row Count 6 (+ 2) % Row 3 \SetRowColor{white} Exists & Has any value & {\emph{tags:}}* \tn % Row Count 8 (+ 2) % Row 4 \SetRowColor{LightBackground} Empty & No values & {\emph{not \_exists\_:tags}} \tn % Row Count 10 (+ 2) % Row 5 \SetRowColor{white} Single match & One specif & {\emph{tags:error}} \tn % Row Count 12 (+ 2) % Row 6 \SetRowColor{LightBackground} Exclude & Remove match & {\emph{not tags:error}} \tn % Row Count 14 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}---} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{1.748 cm} x{1.52 cm} x{4.332 cm} } \SetRowColor{DarkBackground} \mymulticolumn{3}{x{8.4cm}}{\bf\textcolor{white}{Boolean Logic}} \tn % Row 0 \SetRowColor{LightBackground} \{\{bb\}\}{\bf{SYNTAX}} & \{\{bb\}\}{\bf{DESC}} & \{\{bb\}\}{\bf{EXAMPLE}} \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} AND & Both match & {\emph{status:200 and method:GET}} \tn % Row Count 4 (+ 2) % Row 2 \SetRowColor{LightBackground} OR & Either matches & {\emph{status:(200 or 201)}} \tn % Row Count 6 (+ 2) % Row 3 \SetRowColor{white} NOT & Negate & {\emph{not status:400}} \tn % Row Count 7 (+ 1) % Row 4 \SetRowColor{LightBackground} Combined & Mix \seqsplit{operators} & {\emph{status:200 and (user:john or user:svc)}} \tn % Row Count 9 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}---} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{1.9 cm} x{1.9 cm} x{3.8 cm} } \SetRowColor{DarkBackground} \mymulticolumn{3}{x{8.4cm}}{\bf\textcolor{white}{Lists \& Ranges}} \tn % Row 0 \SetRowColor{LightBackground} \{\{bb\}\}{\bf{SYNTAX}} & \{\{bb\}\}{\bf{DESC}} & \{\{bb\}\}{\bf{EXAMPLE}} \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} Value list & Any match & {\emph{status:(200 or 201 or 204)}} \tn % Row Count 4 (+ 2) % Row 2 \SetRowColor{LightBackground} Number range & Between values & {\emph{status \textgreater{}= 200 and status \textless{}= 299}} \tn % Row Count 6 (+ 2) % Row 3 \SetRowColor{white} Date range & Time period & {\emph{@timestamp \textgreater{}= "now-24h"}} \tn % Row Count 8 (+ 2) % Row 4 \SetRowColor{LightBackground} \seqsplit{Multi-field} & Match any field & {\emph{labels.(app:nginx or env:prod)}} \tn % Row Count 10 (+ 2) % Row 5 \SetRowColor{white} Inclusive range & Include 1 and 10 & {\emph{{[}1 to 10{]}}} \tn % Row Count 12 (+ 2) % Row 6 \SetRowColor{LightBackground} Exclusive range & Exclude 1 and 10 & {\emph{\{1 to 10\}}} \tn % Row Count 14 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}---} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{2.28 cm} x{2.28 cm} x{3.04 cm} } \SetRowColor{DarkBackground} \mymulticolumn{3}{x{8.4cm}}{\bf\textcolor{white}{Time Queries}} \tn % Row 0 \SetRowColor{LightBackground} \{\{bb\}\}{\bf{SYNTAX}} & \{\{bb\}\}{\bf{DESC}} & \{\{bb\}\}{\bf{EXAMPLE}} \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} Now & Current time & {\emph{@timestamp \textgreater{}= now}} \tn % Row Count 4 (+ 2) % Row 2 \SetRowColor{LightBackground} Relative & Time offset & {\emph{@timestamp \textgreater{} now-1h}} \tn % Row Count 6 (+ 2) % Row 3 \SetRowColor{white} Calendar & Round to unit & {\emph{@timestamp \textgreater{}= now/d}} \tn % Row Count 8 (+ 2) % Row 4 \SetRowColor{LightBackground} Time units & m, h, d, w, M, y & {\emph{@timestamp \textgreater{} now-7d}} \tn % Row Count 10 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}---} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{2.584 cm} x{2.28 cm} x{2.736 cm} } \SetRowColor{DarkBackground} \mymulticolumn{3}{x{8.4cm}}{\bf\textcolor{white}{Special Cases}} \tn % Row 0 \SetRowColor{LightBackground} \{\{bb\}\}{\bf{SYNTAX}} & \{\{bb\}\}{\bf{DESC}} & \{\{bb\}\}{\bf{EXAMPLE}} \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} Null & Is null & {\emph{tags:null}} \tn % Row Count 3 (+ 1) % Row 2 \SetRowColor{LightBackground} Boolean & True/false & {\emph{active:true}} \tn % Row Count 4 (+ 1) % Row 3 \SetRowColor{white} IP & CIDR format & {\emph{ip:10.0.0.0/24}} \tn % Row Count 6 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}---} \end{tabularx} \par\addvspace{1.3em} % That's all folks \end{multicols*} \end{document}