Original Message:
Sent: 10-09-2025 14:07
From: SBISOC 4430
Subject: Parsed Query and RAW Query
Hi Musaib,
Under Alerts menu, you can view all alerts (which inturn consist of one or more violations) and when you click any alert, you will find Raw Query under Event Details field and Normalized Query under Additional Info field.
Regards,
------------------------------
SBISOC 4430
Manager
Mumbai
------------------------------
Original Message:
Sent: 10-09-2025 01:24
From: Mohammad Musaib Rather
Subject: Parsed Query and RAW Query
Hi Alejandro,
Your response was helpful. Thank you.
when i did retrieve data in audit logs i was able to see the correct query info, in my audit policy events under extended collection is enabled. I want to know about security policies is there any option same as this and when i view logs under violation how to view the query info there as it showing "?" there also.
Your response is highly appreciated, TIA
------------------------------
Mohammad Musaib Rather
Support User
StarLink DMCC
Dubai
Original Message:
Sent: 10-08-2025 10:12
From: Alejandro Hernandez
Subject: Parsed Query and RAW Query
Hi Mohammad
If you want to see the raw query, you need to enable the extended collection in the audit policy to remove the "?" and see the raw query

And in the audit data, you will retrieve event data to the the raw query

------------------------------
Alejandro Hernandez
SICAP
Professional Services Consultant and Principal Technical Trainer
Mexico City