The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →LEQL (Log Entry Query Language) is the clause-based query language Logentries introduced for searching and analyzing log data. Instead of the older pipe-separated form, a LEQL query uses clauses such as where(), groupby() and calculate(). It can return matching log events or produce grouped statistics, depending on the query.
What LEQL is and where it came from
Rapid7 introduced LEQL for Logentries on June 22, 2015, describing it as a SQL-like language for more advanced log analytics. The name stands for Log Entry Query Language. Rapid7’s current Log Search documentation continues to describe LEQL as the language for searching and analyzing logs in its hosted InsightOps environment.
LEQL is not simply a way to find text in a log. A query can filter events, return matching entries, or calculate values across them. That distinction matters: an event search gives you log lines to inspect, while an analytical query can give you counts, sums, or grouped results.
How LEQL differs from the old pipe syntax
The 2015 announcement showed a migration from pipe-separated commands to named clauses. For example:
#1 Best Overall
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- All-in-One Client & Case Tracking: Easily record client details, contact info, program/department, supervisor info, and emergency contacts in one organized place. Log every interaction with space for contact type, mood, stress level, purpose of contact, notes, follow-ups, outcomes, and next appointment date.
- Professional & Easy to Use: Clean, structured layout designed for quick documentation—perfect for case managers, social workers, counselors, and support staff.
- Durable & Travel-Ready: Built with a tough Translux cover to protect your notes on the go. This notebook is perfect for office, field visits, or daily carry, in a convenient 8.5” x 11” size.
- Re Order SKU: LOG-100-7CW-PP(CASE-MANAGEMENT-LOG)
| Syntax | Example | Purpose |
|---|---|---|
| Older Logentries form | pages>0 | GroupBY(dbName) | SUM(pages) |
Filters, groups, then sums using pipe separators. |
| LEQL form | where(pages>0) groupby (dbName) calculate(SUM:pages) |
Expresses the same steps as clauses: filter, group, calculate. |
In the newer form, pipes are removed, and terms are case-insensitive. The launch announcement also said saved queries would be converted automatically during the phased rollout that began July 1, 2015. That rollout date is historical, not a current migration schedule. The [2015 LEQL announcement] described the syntax change and rollout.
How to write a basic LEQL query
Filter events with where()
Use where() to keep events that meet a condition. For example, where(status=500) searches for events whose status value is 500. Conditions can use comparison operators and combine tests; Rapid7’s API documentation includes a saved-query example with where(key1 <= 2 AND key2 > 8).
Rank #2
- EASY TO USE - The manager notebook is easy-to-use that help you keep track of shift notes, employees, etc.
- MONITOR YOUR DATAS - Using a project manager notebook to store all your data, you can track your comps, sales, payments, and customer behavior,consult your records whenever needed.
- HIGH QUALITY - The manager office supplies is used to high quality 100gsm pure white paper, elastic band and a back pocket for extra space. Make sure you have enough space for all manager plan
- UNIQUE DESIGN & A4 SIZE - Manager log book cover is lovely, golden spiral bound design, size of 8.2" x 10.5". Just the perfectly size to fit in your backpack, purse or laptop case. Without taking up your space and always helping you keep track of your small business
- THE PERFECT GIFT - Management logbook as gift for woman & man. Use it to improve your management efficiency, make efficient adjustments whenever needed
Group results with groupby()
Add groupby() when you want to organize matching events by one or more keys, such as a database name, status code, or user. The grouping key determines what each group represents. For example, grouping by status produces separate results for each status value found.
Calculate statistics with calculate()
Use calculate() for an aggregate such as a count or sum. A query such as where(status=500) groupby(service) calculate(COUNT) asks for the number of matching error events per service. Rapid7’s current function list includes count, sum, average, unique, min, max, timeslice, pctl (percentile), bytes, and standard deviation.
Rank #3
- EASY TO USE - The inventory and sales log book are easy-to-use inventory books that help you track inventory, purchases, sales, balances, unit and total costs, and manage reorders - all in one place. Easy track your inventory for small businesses.
- MONITOR YOUR DATAS - Using a sales inventory book to store all your data, you can consult your records whenever needed. Optimize your business and generate the most benefit.
- UNIQUE DESIGN - We make sure you can tailor this inventory log book to your enterprise business needs to take full advantage of its capabilities. It will work for online, consignment, home or in-store businesses.
- HIGH QUALITY - This sales book for your business, sales book size of 5.8" x 8.5", just the perfectly size to fit in your backpack, purse or laptop case. Is used to high quality 100gsm pure white paper, elastic band and a back pocket for extra space.
- THE PERFECT GIFT - Use inventory and sales log book for your personal or samll business finances, give it to your friends, family as a gift for Birthday| Easter|Children's Day|Halloween|Thanksgiving|Christmas|Back to school and New Year's Day.
Event searches versus statistical searches
The result type depends on the query. An event search returns matching log lines, which is useful when you need to inspect individual entries. A statistical search includes calculate() and returns aggregate values; grouping can break those values down by keys. Rapid7’s InsightOps API documentation makes this distinction and shows saved queries that combine filtering, grouping, and time slicing.
- Use event search to find and review specific log entries.
- Use statistical search to count, sum, compare, or otherwise summarize matching data.
- Add grouping when the aggregate needs to be split by a field, rather than reported as one overall value.
See Rapid7’s [Log Search documentation] for the current query components and clause order, and its [InsightOps API documentation] for API search behavior and examples.
Rank #4
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- This Wire-O book contains spaces for managers to keep track of shift notes, employees, etc
- There are spaces to keep lists of top level items as well as daily to-do lists
- You can track your comps, sales, payments, and customer behavior
- 100 Pages, Wire-O, 8.5" x 11" Reorder SKU: LOG-100-7CW-PP(ManagerNotebook)
Current LEQL clauses and execution order
Rapid7’s current documentation lists these components in execution order:
select()chooses the keys to return.where()filters events.groupby()organizes results by key.calculate()performs analysis.having()filters calculated or grouped results.sort()orders results.limit()restricts the number of results.timeslice()divides results into time intervals.
You do not need every clause in every query. A straightforward event search may need only a filter; an analytic query may add grouping, calculation, and time slicing. LEQL also supports regular expressions for pattern matching. Use the current [LEQL Log Search reference] for the precise syntax of individual clauses and operators.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- This Wire-O book contains spaces for you to keep track of tenants, performed and upcoming maintenance, income & expense per property, etc.
- There is enough space for landlords and property managers to track 5 rental properties and 34 tenants
- 100 Pages, Wire-O, 8.5" x 11" - Reorder SKU: LOG-100-7CW(RentalProperty
- Made in USA, Proudly Produced in Ohio. Veteran-Owned.
- Made in the USA: Proudly produced in Ohio by a veteran-owned business; commitment to quality and American craftsmanship
Using timeslice() for trends over time
timeslice() divides data into time buckets so you can compare activity across intervals rather than seeing one total for the whole search period. Rapid7 documents numeric input from 1 to 200 intervals, as well as explicit units such as seconds, minutes, hours, or days. Choose a bucket size that fits the question: short intervals expose brief spikes, while longer intervals make broader trends easier to read.
A time-sliced query is most useful alongside a calculation, such as counting errors per interval. The result then represents a series of aggregates over time, not a list of every event in each bucket. The available intervals and time-unit forms are described in Rapid7’s [analytic functions documentation].
Limits and interpretation of grouped results
Grouping by a field with many distinct values can produce a large number of groups. Rapid7 documents that when a groupby() result exceeds 10,000 unique groups, the output is a statistical approximation. Treat high-cardinality groupings accordingly: they may be useful for a broad overview, but the result should not be mistaken for an exact enumeration of every unique group.
Time slicing and grouping answer different questions. groupby() separates results by a field value; timeslice() separates them by time. A query can use both when you need to compare a measure across categories and intervals, but each additional dimension makes the output more complex to interpret.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteBuilding and using queries in the interface or API
The 2015 LEQL launch described an updated search bar with query-building assistance, autocomplete or type assistance, and validation. Those details refer to the interface announced at launch; current interface labels may differ. For searches through the API, Rapid7 documents both event searches and statistical searches, including saved-query examples using where(), groupby(), and timeslice(). Use the [InsightOps API reference] for current endpoint and request details rather than assuming that a query example alone specifies the full API call.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

