search_query_audits
Search Snowflake query audits using filters like tags, columns, users, and roles to find tag-based or column-based masking events. Returns a search identifier for retrieving results later.
Instructions
Search Snowflake query audits (tag and column masking).
Triggers an async search and returns a search_uuid (valid 30 days).
Use get_query_audit_results with the search_uuid to retrieve
results. All filters are combined with AND logic.
Use this for Snowflake tag-based or column-based masking audits.
For sidecar proxy audits, use search_audits instead.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Max results (default 10000, max 100000). | |
| offset | No | Skip this many results. | |
| from_date_time | No | RFC3339 UTC start time (e.g. "2025-01-01T00:00:00Z"). | |
| to_date_time | No | RFC3339 UTC end time. | |
| executing_role | No | Filter by role executing the query (case-insensitive). | |
| executing_user | No | Filter by user executing the query (case-insensitive). | |
| query_id | No | Filter by query identifier (case-insensitive). | |
| policy_tag_name | No | Filter by policy tag name (case-insensitive). | |
| policy_tag_value | No | Filter by policy tag value (case-insensitive). | |
| policy_column_database_name | No | Filter by database name (case-insensitive). | |
| policy_column_schema_name | No | Filter by schema name (case-insensitive). | |
| policy_column_table_name | No | Filter by table name (case-insensitive). | |
| policy_column_name | No | Filter by column name (case-insensitive). | |
| order_by | No | "asc" or "desc" (default "desc"). | |
| sort_by | No | "event_time" or "rows_accessed" (default "event_time"). |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||