Switch between ES|QL and classic mode
Discover has two query modes: ES|QL mode and classic mode. Classic mode uses data views with Kibana Query Language (KQL) or Lucene.
This page explains how to switch between modes, and what Discover does with your queries when you switch.
- Open Discover. If you're new to ES|QL in Discover, start with Get started with ES|QL in Discover.
- Switching modes applies only to the selected Discover tab. To switch several tabs, repeat the operation for each tab.
When you switch from classic mode to ES|QL mode, Discover converts the existing KQL or Lucene query as follows:
- A KQL query becomes a
WHERE KQL("""<your query text>""")clause, and a Lucene query becomes aWHERE QSTR("""<your query text>""")clause. -
Active filters from the filter bar become WHEREclauses where possible. Discover drops filters that it can't convert, such as scripted filters. -
If the data view has a time field, Discover adds SORTon that field so the newest records appear first. ConvertedWHEREconditions stay in the query.
To switch:
Open the Discover tab you want to switch.
Switch from either location:
- Query in ES|QL (Try ES|QL in earlier versions) in the application menu.
-
Switch to ES|QL in the contextual menu of the active Discover tab. This affects only that tab.
Result: The tab changes to ES|QL mode. If a KQL or Lucene query exists, Discover converts it and runs it.
When you switch from ES|QL mode to classic mode, Discover drops the ES|QL query and keeps the data you were querying:
- Classic mode opens with an empty KQL query. Discover doesn't restore a KQL or Lucene query that it converted when you switched to ES|QL.
- The data view is the one for the data source in the
FROMcommand of the ES|QL query. Discover doesn't reselect a saved data view that you used before switching to ES|QL. - If the data view has a time field, Discover sorts on that field so the newest records appear first.
- The time range and refresh interval stay unchanged.
To switch:
Open the Discover tab that you want to switch to classic mode.
Switch the active tab from either location:
- From the tab's contextual menu, select Switch to classic.
- From the application menu, select Switch to Classic.
This affects only the active Discover tab.
The contextual menu Switch to classic option appears only for the active tab. To see it for another tab, you must load that tab first.
From the application menu, select Switch to classic.
Result: The tab opens in classic mode with an empty KQL query, on the data view for the data source you were querying.