CQL Learning Paths by Example
Learn CQL through curated query examples organized for different audiences and learning goals
Teach CQL from Scratch
Understand what a query is and how events flow through a pipeline. Learn by doing with practical examples that build from basic field operations to calculations and aggregations. Copy and adapt these examples to your queries.
- First Contact (5 examples)
- Filtering & Categorizing (7 examples)
- Counting & Grouping (6 examples)
- Basic Calculations (5 examples)
Skill Up Existing Users
Go beyond basics with time-based analysis, statistical functions, array operations, joins, correlation patterns, and advanced visualization techniques. Copy and adapt these examples to your queries.
- Time & Buckets (6 examples)
- Stats & Percentiles (6 examples)
- Regex & String Extraction (5 examples)
- Array Operations (6 examples)
- Joins, Sessions & Self-Joins (6 examples)
- Correlation & Sequence Detection (11 examples)
- Reshape & Visualize (8 examples)
Onboard Security Analysts
Learn CQL for security investigations with practical examples focused on threat detection, user behavior analysis, network traffic, and detection engineering. Copy and adapt these examples to your queries.
- Log Fundamentals for Analysts (5 examples)
- User & Entity Behavior (5 examples)
- Network & Traffic Analysis (4 examples)
- Detection Engineering (5 examples)
- Advanced Threat Detection (11 examples)
Internal Team Training
Baseline exercises every team member should complete together. Build shared patterns for data enrichment, operational queries, and reusable techniques. Copy and adapt these examples to your queries.
- Common Ground (5 examples)
- Data Enrichment (6 examples)
- Operational Queries (5 examples)
- Advanced & Reusable Patterns (6 examples)
- Testing, Enrichment & Object Arrays (10 examples)
Workshop 1: Teach CQL from Scratch
Zero to querying - for complete newcomers. Work through these examples in order to build a strong foundation. Copy and adapt these examples to your queries.
Stage 1 - First Contact
Understand what a query is and how events flow through a pipeline. These field operations are the foundation of every query you will write - you will use them daily to extract, transform, and enrich your data.
Add Values From Two Fields
examplebeginnerAdd values from two fields
Add a Field Based on Values of Another Field (Ex 1)
examplebeginnerAdd a field based on values of another field (example 1)
Add a Field Based on Values of Another Field (Ex 2)
examplebeginnerAdd a field based on values of another field (example 2)
Check if Field Contains Specific Value
examplebeginnerCheck if field contains specific value
Combine Values of Multiple Fields
examplebeginnerCombine values of multiple fields
Stage 2 - Filtering & Categorizing
Learn to narrow down events, tag them with meaning, and clean out the noise. Production logs contain millions of events - filtering is how you find what matters and ignore what does not.
Categorize Errors in Log Levels
exampleintermediateCategorize errors in log levels
Categorize Events Based on Values in More Fields
exampleintermediateCategorize events based on values in more fields
Compare More Fields and Filter for Specific Events
exampleintermediateCompare more fields and filter for specific events
Compare More Fields and Their Respective Values
exampleintermediateCompare more fields and their respective values
Check if Fields Contain Same Value
exampleintermediateCheck if fields contain same value
Exclude Events With Specific Values From Searches
exampleintermediateExclude events with specific values from searches
Deduplicate Content by Field
exampleintermediateDeduplicate content by field
Stage 3 - Counting & Grouping
Aggregate events into summaries - the heart of log analysis. This is how you turn thousands of raw events into answers: "How many errors per host?" "Which user logged in most?" "What is our traffic volume?"
Bucket Events Summarized by count()
exampleintermediateBucket events summarized by count()
Bucket Events Into Groups
exampleintermediateBucket events into groups
Aggregate Status Codes by count() Per Minute
exampleintermediateAggregate status codes by count() per minute
Calculate Events per Second by Host
exampleintermediateCalculate events per second by host
Calculate Total Log Volume Per Service
exampleintermediateCalculate total log volume per service
Stage 4 - Basic Calculations
Use math and string operations to enrich and shape your data. You will use these constantly to calculate percentages, convert units (bytes to GB), format output, and make results human-readable.
Basic Rounding
exampleintermediateBasic rounding
Calculate Absolute Value
exampleintermediateCalculate absolute value
Calculate HTTP Error Percentages
exampleintermediateCalculate HTTP error percentages
Calculate the Mean of CPU Time
exampleintermediateCalculate the mean of CPU time
Concatenate Fields and Strings Together
exampleintermediateConcatenate fields and strings together
Workshop 2: Skill Up Existing Users
Deepen the craft - for those already querying. Master advanced techniques with practical examples. Copy and adapt these examples to your queries.
Stage 1 - Time & Buckets
Master time-based analysis: intervals, buckets, and sliding windows. Every production query involves time - these techniques let you analyze trends, compare time periods, and detect changes over time.
Assign Current Time of Search Time Interval to Field
exampleintermediateAssign current time of search time interval to field
Assign End of Search Time Interval (Ex 1)
exampleintermediateAssign end of search time interval (example 1)
Assign End of Search Time Interval (Ex 2)
exampleintermediateAssign end of search time interval (example 2)
Bucket Counts When Using bucket()
exampleintermediateBucket counts when using bucket()
Calculate Sum Over Sliding Time-Based Window
exampleintermediateCalculate sum over sliding time-based window
Calculate Sum Over Sliding Window
exampleintermediateCalculate sum over sliding window
Stage 2 - Stats & Percentiles
Go beyond count() - use statistical functions for deep analysis. When averages hide the truth and outliers matter, percentiles reveal what is really happening in your systems.
Annotate Events With Aggregation (Ex 1)
exampleintermediateAnnotate events with aggregation (example 1)
Annotate Events With Aggregation (Ex 2)
exampleintermediateAnnotate events with aggregation (example 2)
Calculate Median Memory Allocation
exampleintermediateCalculate median memory allocation
Calculate Multiple Response Time Percentiles
exampleintermediateCalculate multiple response time percentiles
Calculate Standard Deviation of Bytes Sent
exampleintermediateCalculate standard deviation of bytes sent
Calculate Running Average of Field Values
exampleintermediateCalculate running average of field values
Stage 3 - Regex & String Extraction
Pull structured data from unstructured text - an essential skill for real-world log analysis. Most logs contain valuable data buried in unstructured strings; these techniques let you parse IP addresses, URLs, email addresses, and custom formats without writing parsers.
Extract IP Address and Port From Command Line
exampleintermediateExtract IP address and port from command line
Extract URL Page Names and Find Most Common Pages
exampleintermediateExtract URL page names and find most common pages
Extract Alert Type From Security Event String
exampleintermediateExtract alert type from security event string
Extract Email Local Part
exampleintermediateExtract email local part
Extract Components from Fixed-Length Data
exampleintermediateExtract components from fixed-length data
Stage 4 - Array Operations
Work with structured array data - check, filter, aggregate. Modern logs often contain arrays (tags, labels, nested structures); these functions let you search within arrays, filter by array contents, and aggregate across array elements.
Aggregate Array Content
exampleintermediateAggregate array content
Check for Values in Array
exampleintermediateCheck for values in array
Check For Existence of Element in Given List
exampleintermediateCheck for existence of element in given list
Check For Existence of Element Larger Than Number
exampleintermediateCheck for existence of element larger than number
Calculate Average of Field Values in an Array
exampleintermediateCalculate average of field values in an array
Compute Average Value for Each Array Element With Same Index
exampleintermediateCompute average value for each array element with same index
Stage 5 - Joins, Sessions & Self-Joins
Correlate events across sequences and datasets. When answers require combining data from multiple events or comparing events to each other, these patterns let you join, enrich, and correlate.
Access Fields From Single Neighboring Event (Ex 1)
exampleintermediateAccess fields from single neighboring event (example 1)
Access Fields From Single Neighboring Event (Ex 2)
exampleintermediateAccess fields from single neighboring event (example 2)
Access Fields From Single Neighboring Event (Ex 3)
exampleintermediateAccess fields from single neighboring event (example 3)
Analyze User Sessions Based on Click Activity
exampleintermediateAnalyze user sessions based on click activity
Compare and Filter Values in Same Table
exampleintermediateCompare and filter values in same table
Compare Two Timestamps
exampleintermediateCompare two timestamps
Stage 6 - Correlation & Sequence Detection
Detect multi-event patterns, behavioral sequences, and cross-source correlations. These advanced techniques power threat detection, user journey analysis, and any scenario where you need to detect "Event A followed by Event B within time window X."
Correlate Authentication and Database Errors
exampleadvancedCorrelate authentication and database errors
Correlate Two Scheduled Task Events
exampleadvancedCorrelate two scheduled task events
Correlate AWS Federation Token Generation with Console Logins
exampleintermediateCorrelate AWS federation token generation with console logins
Detect All Occurrences of Event A Before Event B
exampleintermediateDetect all occurrences of event A before event B
Detect Event A Happening X Times Before Event B
exampleintermediateDetect event A happening X times before event B
Detect Event A X Times Before Event B Within a Timespan
exampleintermediateDetect event A X times before event B within a timespan
Detect Two Events Occurring in Quick Succession
exampleintermediateDetect two events occurring in quick succession
Count Events Within Partitions Based on Condition
exampleintermediateCount events within partitions based on condition
Detect Changes And Compute Differences Between Events (Ex 1)
exampleintermediateDetect changes and compute differences between events (example 1)
Detect Changes And Compute Differences Between Events (Ex 2)
exampleintermediateDetect changes and compute differences between events (example 2)
Detect Continuously Upwards Going Trend
exampleintermediateDetect continuously upwards going trend
Stage 7 - Reshape & Visualize
Transform query output into pivot tables, Sankey diagrams, and visual-ready formats. When stakeholders need dashboards or you need to present data visually, these functions reshape your results for charts, graphs, and interactive widgets.
Create a Pivot Table
exampleintermediateCreate a pivot table
Search Across Multiple Structured Fields (transpose in groupBy)
exampleintermediateSearch across multiple structured fields (transpose in groupBy)
Create Data Compatible With Sankey Diagram Widget (Ex 1)
exampleintermediateCreate data compatible with Sankey diagram widget (example 1)
Create Data Compatible With Sankey Diagram Widget (Ex 2)
exampleintermediateCreate data compatible with Sankey diagram widget (example 2)
Create Sankey Diagram Calculating Edge Thickness
exampleintermediateCreate Sankey diagram calculating edge thickness
Calculate Relationship Between X And Y Variables (Ex 1)
exampleintermediateCalculate relationship between X and Y variables (example 1)
Calculate Relationship Between X And Y Variables (Ex 2)
exampleintermediateCalculate relationship between X and Y variables (example 2)
Calculate Relationship Between X And Y Variables (Ex 3)
exampleintermediateCalculate relationship between X and Y variables (example 3)
Workshop 3: Onboard Security Analysts
Detection-first - for SOC and threat hunters. Learn CQL through security-focused query examples. Copy and adapt these examples to your queries.
Stage 1 - Log Fundamentals for Analysts
Understand how to read, filter, and categorize security events. Security analysts need to quickly identify malicious IPs, calculate network ranges, and validate data formats - these queries teach the fundamentals.
Categorize Errors in Log Levels
exampleintermediateCategorize errors in log levels
Check if Field Contains Valid IP Address
exampleintermediateCheck if field contains valid IP address
Calculate Subnet with Custom Prefix Length
exampleintermediateCalculate subnet with custom prefix length
Compute Community ID
exampleintermediateCompute community ID
Alert Query For Parsers Issues
exampleintermediateAlert query for parsers issues
Stage 2 - User & Entity Behavior
Identify anomalous patterns in user activity and logons. Insider threats, compromised accounts, and lateral movement all leave patterns in user behavior - these queries help you detect them.
Analyze User Logon Patterns And Activity
exampleintermediateAnalyze user logon patterns and activity
Analyze User Sessions Based on Click Activity
exampleintermediateAnalyze user sessions based on click activity
Collect and Group Events by Specified Field (Ex 1)
exampleintermediateCollect and group events by specified field (example 1)
Collect and Group Events by Specified Field (Ex 2)
exampleintermediateCollect and group events by specified field (example 2)
Calculate Events per Second by Host
exampleintermediateCalculate events per second by host
Stage 3 - Network & Traffic Analysis
Query network flows and blocked requests. Network traffic patterns reveal C2 communication, data exfiltration, and scanning activity - these queries help you analyze network behavior at scale.
Blocked Requests - Inbound
exampleintermediateBlocked requests - inbound
Blocked Requests - Outbound
exampleintermediateBlocked requests - outbound
Calculate Distance Between Geographical Coordinates
exampleintermediateCalculate distance between geographical coordinates
Calculate Geohash Value of a Set of Coordinates
exampleintermediateCalculate geohash value of a set of coordinates
Stage 4 - Detection Engineering
Build detection-quality queries using entropy, edit distance, and CrowdStrike data. These advanced techniques help you detect domain generation algorithms, typosquatting, obfuscated commands, and other evasion tactics.
Calculate Shannon Entropy Value For String
exampleadvancedCalculate Shannon entropy value for string
Calculate Edit Distance Between Domain Names
exampleadvancedCalculate edit distance between domain names
Compare Domain Names Using Text Edit Distance Array
exampleintermediateCompare domain names using text edit distance array
Analyze Detection Types Distribution
exampleintermediateAnalyze detection types distribution
Access Fields From Neighboring Events (Sequence Analysis)
exampleintermediateAccess fields from neighboring events (sequence analysis)
Stage 5 - Advanced Threat Detection
Multi-event correlation, credential attacks, bitfield decoding, and URL-based threat patterns. These queries combine everything you have learned to detect complex attack chains, credential dumping, and multi-stage threats that span multiple events.
Detect Credential Dumping Activities
exampleadvancedDetect credential dumping activities
Correlate Authentication and Database Errors
exampleintermediateCorrelate authentication and database errors
Correlate AWS Federation Token Generation with Console Logins
exampleintermediateCorrelate AWS federation token generation with console logins
Detect Event A Happening X Times Before Event B
exampleintermediateDetect event A happening X times before event B
Detect Two Events Occurring in Quick Succession
exampleintermediateDetect two events occurring in quick succession
Decode and Extract Bit Flags
exampleintermediateDecode and extract bit flags
Decode and Extract true Bits as Arrays
exampleintermediateDecode and extract true bits as arrays
Decode Redirect URLs in Authentication Logs
exampleintermediateDecode redirect URLs in authentication logs
Decode Referrer URLs in Web Access Logs
exampleintermediateDecode referrer URLs in web access logs
Determine Autonomous System (AS) Number and Organization (Ex 1)
exampleintermediateDetermine autonomous system (AS) number and organization (example 1)
Determine Autonomous System (AS) Number and Organization (Ex 2)
exampleintermediateDetermine autonomous system (AS) number and organization (example 2)
Workshop 4: Internal Team Training
Build shared fluency - for teams adopting LogScale. Baseline exercises every team member should complete together. Copy and adapt these examples to your queries.
Stage 1 - Common Ground
Baseline exercises every team member should complete together. When everyone on the team understands these fundamentals, you can collaborate on queries, review each other's work, and build on a shared foundation.
Add a Field Based on Values of Another Field (Ex 1)
exampleintermediateAdd a field based on values of another field (example 1)
Bucket Events Summarized by count()
exampleintermediateBucket events summarized by count()
Aggregate Status Codes by count() Per Minute
exampleintermediateAggregate status codes by count() per minute
Calculate HTTP Error Percentages
exampleintermediateCalculate HTTP error percentages
Categorize Errors in Log Levels
exampleintermediateCategorize errors in log levels
Stage 2 - Data Enrichment
Enrich and reshape events - core skill for building reusable queries. These patterns let you add context to raw events, making them more meaningful for dashboards, alerts, and analysis that your whole team will use.
Combine Values of Multiple Fields
exampleintermediateCombine values of multiple fields
Concatenate Fields and Strings Together
exampleintermediateConcatenate fields and strings together
Collect and Group Events by Specified Field
exampleintermediateCollect and group events by specified field
Annotate Events With Aggregation (Ex 1)
exampleintermediateAnnotate events with aggregation (example 1)
Annotate Events With Aggregation (Ex 2)
exampleintermediateAnnotate events with aggregation (example 2)
Annotate Events With Aggregation (Ex 3)
exampleintermediateAnnotate events with aggregation (example 3)
Stage 3 - Operational Queries
Queries your team will actually run day-to-day in production. These monitor LogScale itself - ingest lag, query costs, parser health - the operational visibility every LogScale team needs.
Calculate Ingest Queue Compression Ratio Over Time
exampleintermediateCalculate ingest queue compression ratio over time
Calculate and Sort Ingest Lag Times
exampleintermediateCalculate and sort ingest lag times
Calculate Query Cost for All Users by Repository
exampleintermediateCalculate query cost for all users by repository
Calculate Query Costs by User and Repository
exampleintermediateCalculate query costs by user and repository
Alert Query For Parsers Issues
exampleintermediateAlert query for parsers issues
Stage 4 - Advanced & Reusable Patterns
Patterns to standardize across the team - joins, sliding windows, named functions. When your team adopts these patterns, everyone writes queries the same way, making code reviews easier and knowledge transfer faster.
Calculate Sum Over Sliding Time-Based Window
exampleadvancedCalculate sum over sliding time-based window
Compute Cumulative Aggregation Across Buckets
exampleintermediateCompute cumulative aggregation across buckets
Compute Cumulative Aggregation For Specific Group
exampleintermediateCompute cumulative aggregation for specific group
Call Named Function on a Field (Ex 1)
exampleintermediateCall named function on a field (example 1)
Call Named Function on a Field (Ex 2)
exampleintermediateCall named function on a field (example 2)
Concatenate Multiple Tables
exampleintermediateConcatenate multiple tables
Stage 5 - Testing, Enrichment & Object Arrays
Build confidence with synthetic test data, nested JSON structures, and enrichment patterns your team will reuse. These techniques let you test queries without production data, work with complex nested structures, and build reusable enrichment logic.
Create Temporary Events for Troubleshooting (Ex 1)
exampleintermediateCreate temporary events for troubleshooting (example 1)
Create Temporary Events for Troubleshooting (Ex 2)
exampleintermediateCreate temporary events for troubleshooting (example 2)
Create Temporary Events for Troubleshooting (Ex 3)
exampleintermediateCreate temporary events for troubleshooting (example 3)
Check For Existence of Simple Values in Nested Array
exampleintermediateCheck for existence of simple values in nested array
Check for AWS Resources in Vendor Array
exampleintermediateCheck for AWS resources in vendor array
Concatenate Values From Nested Array Elements
exampleintermediateConcatenate values from nested array elements
Concatenate Values From Deeply Nested Array Elements
exampleintermediateConcatenate values from deeply nested array elements
Convert Values Between Units
exampleintermediateConvert values between units
Convert Rate Values
exampleintermediateConvert rate values
Create a Pivot Table
exampleintermediateCreate a pivot table