Skip to main content
Level Blue home page
Search...
⌘K
Support
Dashboard
Dashboard
Search...
Navigation
USM Anywhere Advanced Query
PPL Queries
Home
Documentation
API Reference
Blog
Events
Contact Us
USM Anywhere™
Overview
USM Anywhere Architecture
USM Anywhere Data Security
USM Anywhere Log Data Enhancement
USM Anywhere Quick Start Guides
USM Anywhere Deployment Guide
USM Anywhere User Guides
Overview
Getting Started with USM Anywhere
USM Anywhere Best Practices
USM Anywhere Dashboards
Asset Management
Alarms Management
System Events Management
Console User Events on USM Anywhere
Configuration Issues Management
User Behaviour Analytics
Events Management
USM Anywhere Scheduler
Rules Management
Vulnerability Assessment
Open Threat Exchange® and USM Anywhere
USM Anywhere Sensor Management
USM Anywhere Advanced Query
USM Anywhere Advanced Query
Submitting a custom query
SQL Queries
PPL Queries
Favorite a query
Saving a query
Generating a CSV report
Information to support query writing
List of Fields
The AWS Cloud Connector in USM Anywhere
Subscription Management
USM Anywhere Reports
Machine Learning
USM Anywhere User Management
Using USM Anywhere for PCI Compliance
USM Anywhere Investigations
System Status within USM Anywhere
USM Anywhere Agents Guide
USM Anywhere BlueApps Guide
USM Central™
Overview
USM Central Web User Interface (UI)
USM Central Deployments
Alarms Management
Vulnerabilities
Configuration Issues
Orchestration Rules Management
Saved Reports
System Events Management
User Management
LevelBlue TDR for Gov Documentation
How to Submit a Security Issue to LevelBlue
Automated Policy Manager
Overview
Navigation Panel
Dashboard
Create
Manage
Tickets
Assets
Dark Mode/Light Mode
Early Access Features
Network Based Firewall Service (NBFW)
On this page
PPL query example
USM Anywhere Advanced Query
PPL Queries
USM Anywhere supports queries written in Piped Processing Language (PPL). For syntax guidance, refer to the following:
OpenSearch PPL Overview
OpenSearch PPL Syntax Reference
PPL query example
SQL Queries
Favorite a query
⌘I