Skip to content

aws.cloudtrail.describe_query

Example SQL Queries

SELECT * FROM
aws.cloudtrail.describe_query;

Description

Returns metadata about a query, including query run time in milliseconds, number of events scanned and matched, and query status. If the query results were delivered to an S3 bucket, the response also provides the S3 URI and the delivery status.

You must specify either a QueryID or a QueryAlias. Specifying the QueryAlias parameter returns information about the last query run for the alias.

Table Definition

Column NameColumn Data Type
event_data_store Input Column

The ARN (or the ID suffix of the ARN) of an event data store on which the specified query was run.

VARCHAR
query_alias Input Column

The alias that identifies a query template.

VARCHAR
query_id Input Column

The ID of the query.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
delivery_s3_uri

The URI for the S3 bucket where CloudTrail delivered query results, if applicable.

VARCHAR
delivery_status

The delivery status.

VARCHAR
error_message

The error message returned if a query failed.

VARCHAR
query_statistics

Metadata about a query, including the number of events that were matched, the total number of events scanned, the query run time in milliseconds, and the query's creation time.

STRUCT(
"events_matched" BIGINT,
"events_scanned" BIGINT,
"bytes_scanned" BIGINT,
"execution_time_in_millis" BIGINT,
"creation_time" TIMESTAMP_S
)
Show child fields
query_statistics.bytes_scanned

The total bytes that the query scanned in the event data store. This value matches the number of bytes for which your account is billed for the query, unless the query is still running.

query_statistics.creation_time

The creation time of the query.

query_statistics.events_matched

The number of events that matched a query.

query_statistics.events_scanned

The number of events that the query scanned in the event data store.

query_statistics.execution_time_in_millis

The query's run time, in milliseconds.

query_status

The status of a query. Values for QueryStatus include QUEUED, RUNNING, FINISHED, FAILED, TIMED_OUT, or CANCELLED

VARCHAR
query_string

The SQL code of a query.

VARCHAR