Learn about CQL
Learn CrowdStrike Query Language to search, analyze, and visualize your data
Crowdstrike Query Languages Fundamentals
Begin with CQL basics, understand query structure, learn fundamental concepts, and build a strong foundation before writing complex queries. Perfect for those new to log querying.
- What is CQL?
- Query Structure & Syntax
- Core Concepts (Events, Fields, Tags)
- Your First Queries
Write Queries and Learn to Use CQL
You understand query concepts and are ready to learn CQL specifics. Jump into functions, aggregations, visualizations, and practical query examples for real-world use cases.
- CQL Functions & Operators
- Aggregations & Grouping
- Advanced Query Techniques
- Visualization & Dashboards
Automation, integration, and optimization
You are comfortable with analysis; now you want automation, integration, and optimization. Master advanced query functions, build custom parsers, integrate LogScale with external systems, and automate workflows.
- Advanced Query Functions
- Custom Parser Development
- API Integration & Automation
- Package Management & Publishing
Monitor Applications and Infrastructure
Learn CQL for application performance monitoring, error tracking, and infrastructure health. Covers queries for troubleshooting, deployment monitoring, and platform reliability.
- Application Performance Monitoring
- Error Tracking & Debugging
- Infrastructure Health Checks
- Deployment & Pipeline Monitoring
Reliability and Performance Analysis
Learn CQL for reliability engineering, performance monitoring, and capacity planning. Covers queries for SLI tracking, incident response, and system health analysis.
- Performance & Latency Analysis
- Reliability Metrics & Trends
- Capacity Planning Queries
- Incident Detection & Response
Monitor Infrastructure and System Administration
Learn CQL for infrastructure monitoring, resource tracking, and operational tasks. Covers queries for system health, capacity monitoring, and service availability.
- Resource Usage Monitoring
- System Health Checks
- Service Availability Tracking
- Capacity & Performance Analysis
Business Insights from Log Data
Learn CQL for business analytics, user behavior analysis, and data-driven decision making. Covers queries for product metrics, user journeys, conversion tracking, and business KPIs.
- User Behavior Analysis
- Business Metrics & KPIs
- Conversion Funnels & User Journeys
- Product Analytics & Trends
Threat Hunting and Security Analysis
Learn CQL for security investigations, threat detection, and incident response. Covers queries for authentication analysis, anomaly detection, and security monitoring.
- Threat Detection Queries
- Authentication Analysis
- Security Event Correlation
- Incident Investigation
Workflow 1: New to Query Languages?
Learn the fundamentals of CQL step by step. Understanding these concepts makes writing queries intuitive and effective.
Getting Started with CQL
Understand what CQL is and how to access the query interface
Core Query Concepts
Master the building blocks of every CQL query
Essential Functions
Learn the most commonly used CQL functions
Your First Queries
Practical examples to get you started
Workflow 2: Ready to Write Queries?
Master CQL capabilities in this logical progression from functions to advanced techniques.
Functions & Operators
Master the complete CQL function library
Function Reference
referenceintermediateComplete A-Z reference of all CQL functions
Data Manipulation
referenceintermediateTransform, extract, and enrich fields
Operators
referenceintermediateComparison and logical operators
Calculations
referenceintermediateExpressions, values, and calculations in CQL queries
Aggregations & Grouping
Summarize and group data for analysis
Parsing & Field Extraction
Extract structured data from raw text at query time
parseJson() - Parse JSON
guideintermediateExtract fields from JSON strings in log data
kvParse() - Parse Key-Value Pairs
guideintermediateExtract key-value pairs from unstructured text
regex() - Pattern Matching
referenceintermediateExtract fields using regular expressions
Example: Extract URL Components
exampleintermediateParse URLs and extract page names with regex
Example: Extract Substrings
exampleintermediateExtract alert types from security event strings
Advanced Query Techniques
Master complex query patterns
Joins & Lookups
guideadvancedCombine data from multiple sources
Subqueries and ad-hoc tables
referenceadvancedCreate temporary tables for nested queries
Conditional Logic
referenceintermediatecase() and match() for branching logic
Sequence Detection Functions
referenceintermediateDetect ordered sequences of events
correlate() Function
referenceintermediateMatch and combine related events
Array Functions
referenceintermediateWork with arrays and multi-value fields
Visualization & Dashboards
Turn queries into visual insights.
Selection of widgets depends on the output and type of event set.
LogScale automatically disables incompatible widgets based on your query structure. Use the following guidelines for widget selection when converting table results:
- Time-based data and numerical trends → Time Chart
- Categorical data → Bar Chart / Pie Chart
- Comparisons → Bar Chart
- Distributions → Pie Chart
- Relationships (for example IP address/Port combinations) → Sankey
- Geographic/location data → World Map
- Key metrics → Single Value / Gauge
- Thresholds → Gauge.
Visualization Functions
guideintermediateCharts, graphs, and visual representations
Dashboard Queries
guideintermediateCreate widgets and dashboard visualizations
Selecting Widgets Based on Query Output
guideintermediateChoose the right widget type based on your query results and data structure
Visualizing the Same Query With Different Widgets
guideintermediateLearn how to display query results using multiple widget types for different perspectives
Dashboard Design Best Practices and Templates
guideintermediateBest practices and ready-to-use templates for security monitoring dashboards
Alert Queries
guideintermediateWrite queries for automated alerts
Best Practices & Optimization
Write efficient, maintainable queries
Query Best Practices
guideintermediatePerformance tips, optimization techniques, and common patterns
Troubleshooting Queries
troubleshootingintermediateDebug slow queries, fix errors, and improve performance
Query Examples Library
guideintermediateBrowse the complete library of CQL query examples covering functions, aggregations, parsing, visualization, and advanced techniques. Copy and adjust the code for your own queries.
Workflow 3: Power User & Builder
Master advanced CQL techniques, build custom parsers, integrate LogScale with external systems, and automate workflows for power users and platform builders.
Query Functions (Deep Dive)
Master the less obvious ones:
Write a Parser
Build custom parsers with CQL to structure any log format at ingest time.
CrowdStrike Parsing Standard 1.2
The schema standard for normalized fields - critical if you are building packages or detections.
Search API
Run CQL queries programmatically; integrate LogScale into external workflows.
Actions
Chain query results to webhooks, email, Slack, or other systems.
Package Management & Marketplace
Build and publish reusable query packages (dashboards, saved searches, parsers).
LogScale Internal Architecture
Understanding how the engine works helps you write more performant queries (tag filtering, compaction, and so on).
GraphQL API
Automate everything: repository management, user access, scheduled searches - all via API.
GraphQL API
apiadvancedAutomate everything: repository management, user access, scheduled searches - all via API
GraphQL Queries Reference
referenceadvancedBrowse all available GraphQL queries for retrieving configuration, user, and repository information.
GraphQL Mutations Reference
referenceadvancedBrowse all available GraphQL mutations for creating and managing repositories, users, dashboards, alerts, and more.
Workflow 4: DevOps Engineers
Learn CQL for application monitoring, error tracking, and infrastructure health with practical examples.
Parse & Extract Log Data
Extract structured data from application logs
Parsing Data
guideintermediateParse unstructured logs into structured fields
Field Selection
referenceintermediateSelect, transform, and create fields from log data
regex() Function
referenceintermediateExtract fields using regular expressions
Example: Extract URL Components
exampleintermediateParse URLs and count page access patterns
Example: Deduplicate Logs
exampleintermediateRemove duplicate log entries for cleaner analysis
Track Errors & Performance
Monitor application errors and response times
Aggregate Functions
referenceintermediateCalculate error rates, averages, and percentiles
Query Filters
referenceintermediateFilter events to isolate errors and specific conditions
percentage() Function
referenceintermediateCalculate error rates as percentages
percentile() Function
referenceintermediateCalculate latency percentiles (p50, p95, p99)
Example: HTTP Error Rates
exampleintermediateCalculate client and server error percentages
Example: Response Time Analysis
exampleintermediateCalculate response time percentiles for SLO monitoring
Example: Top Error URLs
exampleintermediateIdentify URLs with highest error counts
Monitor Infrastructure Health
Track platform health and resource utilization
groupBy() Function
referenceintermediateGroup metrics by host, service, or environment
Time Series Analysis
referenceintermediateVisualize metrics over time for trend analysis
count() Function
referenceintermediateCount events for volume and capacity tracking
Example: Hourly Event Patterns
exampleintermediateTrack event volume by hour
Example: Parser Health
exampleintermediateMonitor parser performance and alert on issues
Alerts & Automation
Set up automated alerts and scheduled queries for application monitoring
Example DevOps Dashboards
View real-world application and infrastructure dashboard examples. Select the links below to see full dashboard screenshots and details.
Docker Overview Dashboard
conceptintermediateMonitor container performance and health
Falcon Devices Dashboard
guideintermediateTrack device inventory and health metrics
Query Examples Library
guideintermediateBrowse the complete library of CQL query examples covering functions, aggregations, parsing, visualization, and advanced techniques. Copy and adjust the code for your own queries.
Workflow 5: Site Reliability Engineers (SRE)
Learn CQL for reliability engineering, performance analysis, and capacity planning with practical examples.
Statistical Analysis
Calculate statistical metrics for reliability indicators
Aggregate Functions
referenceintermediateStatistical functions for SLI calculations
groupBy() Function
referenceintermediateGroup metrics by service, region, and endpoint
percentile() Function
referenceintermediateCalculate percentiles for latency and performance SLIs
avg() Function
referenceintermediateCalculate average metrics for baseline comparisons
Example: Latency Percentiles
exampleintermediateCalculate p50, p75, p99, p99.9 for latency analysis
Example: Multi-Field Percentiles
exampleintermediateTrack percentiles across multiple metrics
Trend Detection & Forecasting
Detect trends and predict capacity needs
Sequence Detection Functions
referenceintermediateAnalyze event sequences and detect patterns
bucket() Function
referenceintermediateGroup data by time intervals for trend analysis
slidingWindow() Function
referenceintermediateAnalyze data over sliding event windows
slidingTimeWindow() Function
referenceintermediateAnalyze data over sliding time windows
Example: Trend Detection
exampleintermediateDetect trends using neighbor comparison
Service Health Monitoring
Monitor service reliability and availability
Time Chart Analysis
referenceintermediateTrack availability and error rates over time
Conditional Logic
referenceintermediateUse case statements for health status determination
max() Function
referenceintermediateFind maximum values for SLA breach detection
min() Function
referenceintermediateFind minimum values for baseline performance
Example: SLA Monitoring
exampleintermediateFind slowest response times for SLA tracking
Example: Response Time Ranges
exampleintermediateCalculate min/max response times for SLO validation
Example: Bucket Analysis
exampleintermediateAnalyze metric distribution across ranges
Capacity Planning
Plan capacity and track resource growth
Example SRE Dashboards
View real-world reliability and performance dashboard examples. Select the links below to see full dashboard screenshots and details.
Falcon Spotlight Dashboard
conceptintermediateMonitor system vulnerabilities and reliability
Severity Details Dashboard
guideintermediateTrack severity levels and performance trends
Query Examples Library
guideintermediateBrowse the complete library of CQL query examples covering functions, aggregations, parsing, visualization, and advanced techniques. Copy and adjust the code for your own queries.
Workflow 6: IT Operations (ITOps)
Learn CQL for infrastructure monitoring, system administration, and operational tasks with practical examples.
Query System Data
Search and filter infrastructure logs and metrics
Searching Data
guideintermediateSearch fundamentals for infrastructure logs
Filter System Events
referenceintermediateFilter by host, service, status, and resource type
Operators
referenceintermediateUse comparison and logical operators for filtering
Example: Field Validation
exampleintermediateTest field values for system inventory
Aggregate Resource Metrics
Sum, average, and count infrastructure resources
Aggregate Functions
referenceintermediateCalculate totals, averages, and counts for resources
groupBy() Function
referenceintermediateGroup metrics by host, environment, or cluster
avg() Function
referenceintermediateCalculate average resource utilization
sum() Function
referenceintermediateSum total resource consumption
count() Function
referenceintermediateCount systems, events, and resources
Example: CPU Utilization
exampleintermediateCalculate and format average CPU usage
Example: CPU Range Distribution
exampleintermediateGroup CPU usage into ranges for analysis
Example: Event Counts
exampleintermediateCount events per repository for capacity tracking
Monitor System Health
Track system status and detect failures
Health Over Time
referenceintermediateTrack system health metrics in time series
top() Function
referenceintermediateIdentify top resource consumers or failing systems
Example: Detect Offline Nodes
exampleintermediateIdentify offline or unhealthy nodes
Example: Failed Requests
exampleintermediateTrack failed requests for system health
Example: Hourly Health Patterns
exampleintermediateMonitor system health patterns over time
Capacity & Trend Analysis
Analyze capacity and identify growth trends
bucket() Function
referenceintermediateGroup capacity data by time intervals
percentile() Function
referenceintermediateCalculate percentiles for capacity threshold planning
Example: CPU Trends
exampleintermediateVisualize CPU trends with windowing
Example: Resource Allocation
exampleintermediateCalculate percentiles for capacity planning
Example ITOps Dashboards
View real-world infrastructure monitoring dashboard examples. Select the links below to see full dashboard screenshots and details.
Device Overview Dashboard
conceptintermediateMonitor device inventory, health, and status
Device Policies Dashboard
guideintermediateTrack policy compliance and configuration management
Query Examples Library
guideintermediateBrowse the complete library of CQL query examples covering functions, aggregations, parsing, visualization, and advanced techniques. Copy and adjust the code for your own queries.
Workflow 7: Data Analysts
Learn CQL for business analytics, user behavior analysis, and extracting insights from log data with practical examples.
Understanding Log Data for Business
Extract business-relevant data from application and user event logs
Searching Data
guideintermediateSearch fundamentals for finding user and business events
Filter Events
referenceintermediateFilter by user ID, session, feature, or business event type
Field Extraction
referenceintermediateExtract user attributes, event properties, and business metrics
top() Function
referenceintermediateIdentify top users, features, or products by activity
Example: Find Top Values
exampleintermediateFind most common values across any dimension
Track User Behavior & Journeys
Analyze user sessions, paths, and interaction patterns
Sequence Detection Functions
referenceintermediateTrack user journey steps and event sequences
groupBy() Function
referenceintermediateGroup events by user, session, or customer segment
Joins & Lookups
guideintermediateEnrich user events with customer or product data
match() Function
referenceintermediateMatch user behavior patterns and segment users
Example: Group and Sort Events
exampleintermediateGroup events by user and sort by timestamp
Example: Count Session Visitors
exampleintermediateCount unique visitors per session
Example: Sort Visitors by Activity
exampleintermediateSort visitors by activity level or session count
Calculate Business Metrics & KPIs
Compute conversion rates, retention, and key business metrics
Aggregate Functions
referenceintermediateCalculate counts, sums, averages for business metrics
percentage() Function
referenceintermediateCalculate conversion rates and success rates
count() Function
referenceintermediateCount users, sessions, conversions, or events
sum() Function
referenceintermediateSum revenue, transactions, or business values
Conditional Logic
referenceintermediateUse case statements to categorize users or events
Example: Calculate Percentages
exampleintermediateCalculate rates and percentages for business metrics
Trend Analysis & Time-Based Insights
Analyze trends over time, detect patterns, and identify growth opportunities
timechart() Function
referenceintermediateVisualize business metrics over time
bucket() Function
referenceintermediateGroup data by time periods for trend analysis
slidingTimeWindow() Function
referenceintermediateCalculate rolling averages and moving metrics
Visualization Functions
guideintermediateCreate charts and graphs for business reporting
worldMap() Function
referenceintermediateVisualize data on geographic maps
sankey() Function
referenceintermediateCreate flow diagrams to visualize user journeys
Example: Count Events Over Time
exampleintermediateTrack event counts in time series
Example: Multi-Metric Trends
exampleintermediateTrack multiple business metrics over time
Example: Hourly Patterns
exampleintermediateIdentify usage patterns by time of day
Example: Geographic Analysis
exampleintermediateAdd geographic location data to analyze user distribution
Example: User Flow Visualization
exampleintermediateVisualize user navigation flows with Sankey diagrams
Example Analytics Dashboards
View real-world analytics dashboard examples. Select the links below to see full dashboard screenshots and details.
User Activity Dashboard
guideintermediateTrack user activity patterns and behavior
Web Activity Dashboard
guideintermediateMonitor web usage and access patterns
Query Examples Library
guideintermediateBrowse the complete library of CQL query examples covering functions, aggregations, parsing, visualization, and advanced techniques. Copy and adjust the code for your own queries.
Workflow 8: Security Operations (SecOps)
Learn CQL for security analysis, threat hunting, and incident response with practical examples.
Search & Filter Security Data
Learn to search and filter security logs efficiently
Searching Data
guideintermediateSearch fundamentals and query structure for security logs
Query Filters
referenceintermediateFilter security events using field comparisons and wildcards
Regular Expressions
referenceintermediateUse regex patterns to match security indicators and threats
cidr() Function
referenceintermediateFilter events by IP address ranges and subnets
match() Function
referenceintermediateMatch events against threat patterns
Example: Filter by IP Range
exampleintermediateFilter events using CIDR subnets for network analysis
Example: Categorize Events
exampleintermediateCount and compare security event categories
Correlate Security Events
Link related security events to detect attack patterns
Event Correlation
referenceintermediateMatch and combine events to detect multi-stage attacks
Joins & Lookups
guideintermediateEnrich security data with threat intelligence lookups
Sequence Detection Functions
referenceintermediateDetect ordered sequences of security events
Example: Task Event Correlation
exampleintermediateCorrelate scheduled task registration and deletion
Example: AWS Login Correlation
exampleintermediateCorrelate AWS federation and console login events
Example: IOC Detection
exampleintermediateDetect indicators of compromise with IP lookups
Analyze Security Trends
Track security events over time and identify anomalies
Aggregate Functions
referenceintermediateCount, group, and summarize security events
groupBy() Function
referenceintermediateGroup events by attacker, target, or threat type
top() Function
referenceintermediateIdentify top attackers, targets, or threat indicators
Visualize Security Data
guideintermediateCreate charts and visualizations for security dashboards
Example: Authentication Timeline
exampleintermediateCorrelate authentication attempts with database errors
Alerts & Automation
Set up automated alerts and scheduled queries for security monitoring
What are Triggers
guideintermediateUnderstand trigger types: Scheduled Search, Aggregate Alert, Filter Alert
Automated Queries
guideintermediateCreate scheduled queries and security alerts
Actions
guideintermediateConfigure actions for notifications and integrations
Example: Parser Alerts
exampleintermediateAlert on parser failures and issues
Example Security Dashboards
View real-world security dashboard examples. Select the links below to see full dashboard screenshots and details.
SIEM Connector Detections Dashboard
guideintermediateView detection patterns and security alerts
Intel Indicators Dashboard
conceptintermediateTrack threat intelligence and IOCs
Query Examples Library
guideintermediateBrowse the complete library of CQL query examples covering functions, aggregations, parsing, visualization, and advanced techniques. Copy and adjust the code for your own queries.