Execute a query
It is important to know how to execute a query correctly in Vantage.
Note: Strings are always "quoted", otherwise they are interpreted as data fields. For
example, you can write a query similar to
alerts | where closed_time >
time
to compare two fields.Note: When you access a JSON sub
field, occurrences of
\
are translated to .
For
example, os:info/source
becomes os:info.source
in
the resulting dataset.- In the top navigation bar, select Queries.
-
Choose a method to show the available data sources.
- In the Query text field, select Ctrl+Space.
- In the Query text field, enter the first few letters of a data source.
A list of available data sources shows. - Enter your query.
-
Select Execute (Cmd+Enter).
The results of your query show.
- If necessary, select Save to save the query for future use.
- If necessary, select Save Assertion to save the assertion for future use.
- If necessary, select Export and choose Excel or CSV as an export format.