QRadar AQL Assistant
Build QRadar AQL queries field by field, validate clause order and syntax, and explain what a query does. Everything runs in your browser.
1. Data source
2. Fields
Field, optional function wrapper, optional alias. COUNT becomes COUNT(*); DATEFORMAT gets a date pattern.
3. Filters (WHERE)
4. Aggregation
5. Sorting & limit
6. Time range
Generated query
Ctrl+Enter validates.
Validation results
Corrected query
Ctrl+Enter explains.
How it works
The assistant reads the query as text: it finds the top-level clauses (ignoring anything inside quotes or parentheses), checks them against AQL's rules and describes each part. Nothing is sent to a server and no QRadar connection is needed.
- Builder: pick
eventsorflows, the fields (with an optional function such asQIDNAME,COUNTorDATEFORMATand an alias), WHERE conditions, GROUP BY / HAVING, ORDER BY, LIMIT and a time range. The query updates live. - Validator flags: missing or unknown
FROMtable (V05), clauses out of order (V04, expected order SELECT, FROM, WHERE, GROUP BY, HAVING, ORDER BY, LIMIT, then LAST or START/STOP),LIMITafter the time clause (V02),HAVINGwithoutGROUP BY(V03),TEXT SEARCHnot first in WHERE (V01) or combined withOR(V08), string values in double quotes instead of single quotes (V06) and invalidLASTunits (V09). Simple fixes (quotes, OR with TEXT SEARCH) are applied to a corrected copy. - Explainer summarises the data source, filters, aggregation, sorting, time range and every recognised function, with performance notes (TEXT SEARCH on long windows,
SELECT *, no time clause means the last 5 minutes).
It is a pattern-based helper, not QRadar's parser: custom properties, subqueries and less common functions are not checked. Always run the final query in QRadar. For ready-made detection logic, see the Sigma Rule Builder, which also exports basic AQL.