ppl-reference

Installation
SKILL.md

PPL Language Reference

Overview

This is a comprehensive reference for the Piped Processing Language (PPL) used by OpenSearch. PPL queries follow a pipe-delimited syntax starting with source=<index> and chaining commands with |. This reference covers all commands, functions, API endpoints, and usage patterns needed to construct observability queries against trace and log indices.

Grammar sourced from the opensearch-project/sql repository's docs/user/ppl/ directory: https://github.com/opensearch-project/sql

Connection Defaults

Variable Default Description
OPENSEARCH_ENDPOINT https://localhost:9200 OpenSearch base URL
OPENSEARCH_USER admin OpenSearch username
OPENSEARCH_PASSWORD My_password_123!@# OpenSearch password

Field Name Escaping

Installs
1
GitHub Stars
25
First Seen
Jun 20, 2026
ppl-reference — opensearch-project/observability-stack