ezgh trails query run "<SQL>" [--from t] [--to t] [--async] [flags]Run a Trails query over the table trails, for the window --from (inclusive) to --to (exclusive): the last 7 days by default, at most 90. ezgh waits for it, polling at the interval Trails suggests, then prints its rows page by page. --async prints the query’s ID straight away instead; follow it with ezgh trails query get|results. Ctrl-C while waiting cancels the query.
Part of ezgh trails query.
Examples
ezgh trails query run "SELECT event_name, count() AS n FROM trails GROUP BY event_name ORDER BY n DESC" --from 30d
ezgh trails query run "SELECT event_time, principal_id FROM trails WHERE error_code = 'access_denied'" --async
ezgh trails query schemaFlags
| Flag | Type | Default | Description |
|---|---|---|---|
--async |
boolean | print the query ID and return without waiting | |
--from |
string | the window’s start (default: 7 days before --to) |
|
--limit |
int | rows per page read, 1 to 1000 (default 100) | |
--to |
string | the window’s end (default: now) |
This command also takes the global flags.