← All Tools

QRadar AQL Assistant

Build QRadar AQL queries field by field, validate clause order and syntax, and explain what a query does. Everything runs in your browser.

1. Data source

2. Fields

3. Filters (WHERE)

4. Aggregation

5. Sorting & limit

6. Time range

Generated query


                    

Ctrl+Enter validates.

Ctrl+Enter explains.

How it works

The assistant reads the query as text: it finds the top-level clauses (ignoring anything inside quotes or parentheses), checks them against AQL's rules and describes each part. Nothing is sent to a server and no QRadar connection is needed.

  • Builder: pick events or flows, the fields (with an optional function such as QIDNAME, COUNT or DATEFORMAT and an alias), WHERE conditions, GROUP BY / HAVING, ORDER BY, LIMIT and a time range. The query updates live.
  • Validator flags: missing or unknown FROM table (V05), clauses out of order (V04, expected order SELECT, FROM, WHERE, GROUP BY, HAVING, ORDER BY, LIMIT, then LAST or START/STOP), LIMIT after the time clause (V02), HAVING without GROUP BY (V03), TEXT SEARCH not first in WHERE (V01) or combined with OR (V08), string values in double quotes instead of single quotes (V06) and invalid LAST units (V09). Simple fixes (quotes, OR with TEXT SEARCH) are applied to a corrected copy.
  • Explainer summarises the data source, filters, aggregation, sorting, time range and every recognised function, with performance notes (TEXT SEARCH on long windows, SELECT *, no time clause means the last 5 minutes).

It is a pattern-based helper, not QRadar's parser: custom properties, subqueries and less common functions are not checked. Always run the final query in QRadar. For ready-made detection logic, see the Sigma Rule Builder, which also exports basic AQL.