Tutorials · Result workflow

From broad query to useful evidence

A useful result is small enough to review, clear enough to explain and reproducible from saved SQL.

1. Begin broad—but limited

Return useful columns and a small number of rows. Confirm timestamps and representative values.

2. Narrow the incident window

Add time, status, user, host, source or path filters.

3. Aggregate before exporting

Use COUNT, AVG, MAX and GROUP BY to identify patterns, then query detail rows.

4. Validate in the grid

Sort, filter and check outliers. Save the final SQL with a descriptive name.

5. Export only what matters

Choose Excel or CSV for analysis, JSON or XML for exchange, or HTML for a readable snapshot.