Skip to content

ezgh trails query run

Run a query: wait for it and print its rows as they're read.

Updated View as Markdown
ezgh trails query run "<SQL>" [--from t] [--to t] [--async] [flags]

Run a Trails query over the table trails, for the window --from (inclusive) to --to (exclusive): the last 7 days by default, at most 90. ezgh waits for it, polling at the interval Trails suggests, then prints its rows page by page. --async prints the query’s ID straight away instead; follow it with ezgh trails query get|results. Ctrl-C while waiting cancels the query.

Part of ezgh trails query.

Examples

ezgh trails query run "SELECT event_name, count() AS n FROM trails GROUP BY event_name ORDER BY n DESC" --from 30d
ezgh trails query run "SELECT event_time, principal_id FROM trails WHERE error_code = 'access_denied'" --async
ezgh trails query schema

Flags

Flag Type Default Description
--async boolean print the query ID and return without waiting
--from string the window’s start (default: 7 days before --to)
--limit int rows per page read, 1 to 1000 (default 100)
--to string the window’s end (default: now)

This command also takes the global flags.

Navigation

Type to search…

↑↓ navigate↵ selectEsc close