1. Begin broad—but limited
Return useful columns and a small number of rows. Confirm timestamps and representative values.
2. Narrow the incident window
Add time, status, user, host, source or path filters.
3. Aggregate before exporting
Use COUNT, AVG, MAX and GROUP BY to identify patterns, then query detail rows.
4. Validate in the grid
Sort, filter and check outliers. Save the final SQL with a descriptive name.
5. Export only what matters
Choose Excel or CSV for analysis, JSON or XML for exchange, or HTML for a readable snapshot.