7 synthetic input rows in security_audit_events. Timestamps shift into the current query window when the fixture loads.
Results are capped at 500 rows. The included fixtures are synthetic and intentionally small.
No fixture or query is sent to Telemetry.
Published expected result
Query output and visualization
Query result
Privileged-action failure rate
Data exports have the highest denied or failed share in the synthetic review set.
| action | actions | failed_actions | review_required | failure_rate_pct |
|---|---|---|---|---|
| data_exported | 2 | 1 | 1 | 50 |
| permissions_changed | 3 | 1 | 2 | 33.33 |
| api_key_created | 2 | 0 | 1 | 0 |
Synthetic example output. Run the query against your own event schema and thresholds before using it for operational decisions.
What this playground proves—and what it does not
The browser runner proves that the selected read-only query executes against its included rows and produces the displayed result. The browser downloads the versioned DuckDB runtime from jsDelivr only after you run a query; the SQL and fixture are not sent with that request. Telemetry recipes are separately planned with Apache DataFusion, the engine used by Telemetry. DuckDB and DataFusion are distinct SQL engines, so validate any edited syntax with the DataFusion SQL reference before using it in production.