<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DB connect query field need to create in splunk data in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-connect-query-field-need-to-create-in-splunk-data/m-p/449046#M55237</link>
    <description>&lt;P&gt;you could have a field say &lt;CODE&gt;| eval  query_runTime = _time&lt;/CODE&gt; in your search , which will populate the time and it can be stored in the index. everytime you run, you will have the time (including ms). would this not help?&lt;/P&gt;</description>
    <pubDate>Tue, 19 Mar 2019 10:30:19 GMT</pubDate>
    <dc:creator>lakshman239</dc:creator>
    <dc:date>2019-03-19T10:30:19Z</dc:date>
    <item>
      <title>DB connect query field need to create in splunk data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-connect-query-field-need-to-create-in-splunk-data/m-p/449045#M55236</link>
      <description>&lt;P&gt;Hi Friends,&lt;/P&gt;

&lt;P&gt;I have DB connect query which runs from 1 to 7th date of every month.&lt;/P&gt;

&lt;P&gt;I need one field to be create in splunk data if query is run out of date from 1 to 7th of every month. Suppose query is re-run manually on 8th then it should create one field in splunk data. Could we create such automation in splunk&lt;/P&gt;

&lt;P&gt;I required such arrangement as we are trying to compare count of data injected from database with count of data in splunk. I could not use date as field as data keep changing in mili seconds.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 08:44:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-connect-query-field-need-to-create-in-splunk-data/m-p/449045#M55236</guid>
      <dc:creator>rakesh44</dc:creator>
      <dc:date>2019-03-19T08:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: DB connect query field need to create in splunk data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-connect-query-field-need-to-create-in-splunk-data/m-p/449046#M55237</link>
      <description>&lt;P&gt;you could have a field say &lt;CODE&gt;| eval  query_runTime = _time&lt;/CODE&gt; in your search , which will populate the time and it can be stored in the index. everytime you run, you will have the time (including ms). would this not help?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 10:30:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-connect-query-field-need-to-create-in-splunk-data/m-p/449046#M55237</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-03-19T10:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: DB connect query field need to create in splunk data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-connect-query-field-need-to-create-in-splunk-data/m-p/449047#M55238</link>
      <description>&lt;P&gt;There two things when DB connect query runs it pull data from oracle and put it in splunk Index.&lt;BR /&gt;
In my case if DB connect query runs it should create one field in splunk Index.  Then I would count no fields in splunk.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 09:25:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-connect-query-field-need-to-create-in-splunk-data/m-p/449047#M55238</guid>
      <dc:creator>rakesh44</dc:creator>
      <dc:date>2019-03-20T09:25:40Z</dc:date>
    </item>
  </channel>
</rss>

