Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

LEQL (Log Entry Query Language) is the clause-based query language Logentries introduced for searching and analyzing log data. Instead of the older pipe-separated form, a LEQL query uses clauses such as where(), groupby() and calculate(). It can return matching log events or produce grouped statistics, depending on the query.

What LEQL is and where it came from

Rapid7 introduced LEQL for Logentries on June 22, 2015, describing it as a SQL-like language for more advanced log analytics. The name stands for Log Entry Query Language. Rapid7’s current Log Search documentation continues to describe LEQL as the language for searching and analyzing logs in its hosted InsightOps environment.

LEQL is not simply a way to find text in a log. A query can filter events, return matching entries, or calculate values across them. That distinction matters: an event search gives you log lines to inspect, while an analytical query can give you counts, sums, or grouped results.

How LEQL differs from the old pipe syntax

The 2015 announcement showed a migration from pipe-separated commands to named clauses. For example:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
BookFactory Case Management Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • All-in-One Client & Case Tracking: Easily record client details, contact info, program/department, supervisor info, and emergency contacts in one organized place. Log every interaction with space for contact type, mood, stress level, purpose of contact, notes, follow-ups, outcomes, and next appointment date.
  • Professional & Easy to Use: Clean, structured layout designed for quick documentation—perfect for case managers, social workers, counselors, and support staff.
  • Durable & Travel-Ready: Built with a tough Translux cover to protect your notes on the go. This notebook is perfect for office, field visits, or daily carry, in a convenient 8.5” x 11” size.
  • Re Order SKU: LOG-100-7CW-PP(CASE-MANAGEMENT-LOG)
Syntax Example Purpose
Older Logentries form pages>0 | GroupBY(dbName) | SUM(pages) Filters, groups, then sums using pipe separators.
LEQL form where(pages>0) groupby (dbName) calculate(SUM:pages) Expresses the same steps as clauses: filter, group, calculate.

In the newer form, pipes are removed, and terms are case-insensitive. The launch announcement also said saved queries would be converted automatically during the phased rollout that began July 1, 2015. That rollout date is historical, not a current migration schedule. The [2015 LEQL announcement] described the syntax change and rollout.

How to write a basic LEQL query

Filter events with where()

Use where() to keep events that meet a condition. For example, where(status=500) searches for events whose status value is 500. Conditions can use comparison operators and combine tests; Rapid7’s API documentation includes a saved-query example with where(key1 <= 2 AND key2 > 8).

Rank #2
Heveboik Manager Notebook - Manager's Log Book Planner Management Logbook, Spiral Bound, Inner Pocket, 8.2'' X 10.5", Black
  • EASY TO USE - The manager notebook is easy-to-use that help you keep track of shift notes, employees, etc.
  • MONITOR YOUR DATAS - Using a project manager notebook to store all your data, you can track your comps, sales, payments, and customer behavior,consult your records whenever needed.
  • HIGH QUALITY - The manager office supplies is used to high quality 100gsm pure white paper, elastic band and a back pocket for extra space. Make sure you have enough space for all manager plan
  • UNIQUE DESIGN & A4 SIZE - Manager log book cover is lovely, golden spiral bound design, size of 8.2" x 10.5". Just the perfectly size to fit in your backpack, purse or laptop case. Without taking up your space and always helping you keep track of your small business
  • THE PERFECT GIFT - Management logbook as gift for woman & man. Use it to improve your management efficiency, make efficient adjustments whenever needed

Group results with groupby()

Add groupby() when you want to organize matching events by one or more keys, such as a database name, status code, or user. The grouping key determines what each group represents. For example, grouping by status produces separate results for each status value found.

Calculate statistics with calculate()

Use calculate() for an aggregate such as a count or sum. A query such as where(status=500) groupby(service) calculate(COUNT) asks for the number of matching error events per service. Rapid7’s current function list includes count, sum, average, unique, min, max, timeslice, pctl (percentile), bytes, and standard deviation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Heveboik Inventory & Sales Log Book for Small Business – Inventory Ledger Book, Inventory Notebook, Order Tracker for Purchases, Sales & Reorders, 5.8" x 8.5", Black
  • EASY TO USE - The inventory and sales log book are easy-to-use inventory books that help you track inventory, purchases, sales, balances, unit and total costs, and manage reorders - all in one place. Easy track your inventory for small businesses.
  • MONITOR YOUR DATAS - Using a sales inventory book to store all your data, you can consult your records whenever needed. Optimize your business and generate the most benefit.
  • UNIQUE DESIGN - We make sure you can tailor this inventory log book to your enterprise business needs to take full advantage of its capabilities. It will work for online, consignment, home or in-store businesses.
  • HIGH QUALITY - This sales book for your business, sales book size of 5.8" x 8.5", just the perfectly size to fit in your backpack, purse or laptop case. Is used to high quality 100gsm pure white paper, elastic band and a back pocket for extra space.
  • THE PERFECT GIFT - Use inventory and sales log book for your personal or samll business finances, give it to your friends, family as a gift for Birthday| Easter|Children's Day|Halloween|Thanksgiving|Christmas|Back to school and New Year's Day.

Event searches versus statistical searches

The result type depends on the query. An event search returns matching log lines, which is useful when you need to inspect individual entries. A statistical search includes calculate() and returns aggregate values; grouping can break those values down by keys. Rapid7’s InsightOps API documentation makes this distinction and shows saved queries that combine filtering, grouping, and time slicing.

  • Use event search to find and review specific log entries.
  • Use statistical search to count, sum, compare, or otherwise summarize matching data.
  • Add grouping when the aggregate needs to be split by a field, rather than reported as one overall value.

See Rapid7’s [Log Search documentation] for the current query components and clause order, and its [InsightOps API documentation] for API search behavior and examples.

Rank #4
BookFactory Manager's Log Book Planner, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • This Wire-O book contains spaces for managers to keep track of shift notes, employees, etc
  • There are spaces to keep lists of top level items as well as daily to-do lists
  • You can track your comps, sales, payments, and customer behavior
  • 100 Pages, Wire-O, 8.5" x 11" Reorder SKU: LOG-100-7CW-PP(ManagerNotebook)

Current LEQL clauses and execution order

Rapid7’s current documentation lists these components in execution order:

  1. select() chooses the keys to return.
  2. where() filters events.
  3. groupby() organizes results by key.
  4. calculate() performs analysis.
  5. having() filters calculated or grouped results.
  6. sort() orders results.
  7. limit() restricts the number of results.
  8. timeslice() divides results into time intervals.

You do not need every clause in every query. A straightforward event search may need only a filter; an analytic query may add grouping, calculation, and time slicing. LEQL also supports regular expressions for pattern matching. Use the current [LEQL Log Search reference] for the precise syntax of individual clauses and operators.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
BookFactory Rental Property Record Book, Wire-O, 100 Pages
  • This Wire-O book contains spaces for you to keep track of tenants, performed and upcoming maintenance, income & expense per property, etc.
  • There is enough space for landlords and property managers to track 5 rental properties and 34 tenants
  • 100 Pages, Wire-O, 8.5" x 11" - Reorder SKU: LOG-100-7CW(RentalProperty
  • Made in USA, Proudly Produced in Ohio. Veteran-Owned.
  • Made in the USA: Proudly produced in Ohio by a veteran-owned business; commitment to quality and American craftsmanship
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Using timeslice() for trends over time

timeslice() divides data into time buckets so you can compare activity across intervals rather than seeing one total for the whole search period. Rapid7 documents numeric input from 1 to 200 intervals, as well as explicit units such as seconds, minutes, hours, or days. Choose a bucket size that fits the question: short intervals expose brief spikes, while longer intervals make broader trends easier to read.

A time-sliced query is most useful alongside a calculation, such as counting errors per interval. The result then represents a series of aggregates over time, not a list of every event in each bucket. The available intervals and time-unit forms are described in Rapid7’s [analytic functions documentation].

Limits and interpretation of grouped results

Grouping by a field with many distinct values can produce a large number of groups. Rapid7 documents that when a groupby() result exceeds 10,000 unique groups, the output is a statistical approximation. Treat high-cardinality groupings accordingly: they may be useful for a broad overview, but the result should not be mistaken for an exact enumeration of every unique group.

Time slicing and grouping answer different questions. groupby() separates results by a field value; timeslice() separates them by time. A query can use both when you need to compare a measure across categories and intervals, but each additional dimension makes the output more complex to interpret.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Building and using queries in the interface or API

The 2015 LEQL launch described an updated search bar with query-building assistance, autocomplete or type assistance, and validation. Those details refer to the interface announced at launch; current interface labels may differ. For searches through the API, Rapid7 documents both event searches and statistical searches, including saved-query examples using where(), groupby(), and timeslice(). Use the [InsightOps API reference] for current endpoint and request details rather than assuming that a query example alone specifies the full API call.

Quick Recap

Bestseller No. 1
BookFactory Case Management Log Book, Wire-O, 100 Pages
BookFactory Case Management Log Book, Wire-O, 100 Pages
Made in USA - Proudly produced in Ohio by a Veteran-owned business; Re Order SKU: LOG-100-7CW-PP(CASE-MANAGEMENT-LOG)
$19.99
Bestseller No. 4
BookFactory Manager's Log Book Planner, Wire-O, 100 Pages
BookFactory Manager's Log Book Planner, Wire-O, 100 Pages
Made in USA - Proudly produced in Ohio by a Veteran-owned business; This Wire-O book contains spaces for managers to keep track of shift notes, employees, etc
$17.99
Bestseller No. 5
BookFactory Rental Property Record Book, Wire-O, 100 Pages
BookFactory Rental Property Record Book, Wire-O, 100 Pages
100 Pages, Wire-O, 8.5" x 11" - Reorder SKU: LOG-100-7CW(RentalProperty; Made in USA, Proudly Produced in Ohio. Veteran-Owned.
$22.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.