Create or edit a query with the CloudTrail console
In this walkthrough, we open one of the sample queries, edit it to find actions taken by a specific user named Alice, and save it as a new query. You can also edit a saved
            query on the Saved queries tab, if you have saved queries. To help control costs, we recommend that you constrain queries by adding starting and
            ending eventTime time stamps to queries.
- 
                Sign in to the AWS Management Console and open the CloudTrail console at https://console.aws.amazon.com/cloudtrail/ . 
- 
                From the navigation pane, under Lake, choose Query. 
- 
                On the Query page, choose the Sample queries tab. 
- 
                Open a sample query by choosing the Query name. This opens the query in the Editor tab. In this example, we'll select the query named Investigate user actions and edit the query to find the actions for a specific user named Alice.
- 
                In the Editor tab, edit the WHEREline to specify the user that you want to investigate and update theeventTimevalues as needed. The value ofFROMis the ID portion of the event data store's ARN and is automatically populated by CloudTrail when you choose the event data store.SELECT eventID, eventName, eventSource, eventTime, userIdentity.arn AS user FROMevent-data-store-idWHERE userIdentity.arn LIKE '%Alice%' AND eventTime > '2023-06-23 00:00:00' AND eventTime < '2023-06-26 00:00:00'
- 
                You can run a query before you save it, to verify that the query works. To run a query, choose an event data store from the Event data store drop-down list, and then choose Run. View the Status column of the Command output tab for the active query to verify that a query ran successfully. 
- 
                When you have updated the sample query, choose Save. 
- 
                In Save query, enter a name and description for the query. Choose Save query to save your changes as the new query. To discard changes to a query, choose Cancel, or close the Save query window.   NoteSaved queries are tied to your browser; if you use a different browser or a different device to access the CloudTrail console, the saved queries are not available. 
- 
                Open the Saved queries tab to see the new query in the table. 