<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can I use epoch as timestamp in DBConnect? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-use-epoch-as-timestamp-in-DBConnect/m-p/648294#M110219</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/45250"&gt;@wmuselle&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;For raising column&lt;UL&gt;&lt;LI&gt;You should be able to use that column as a raising column without any change&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;For timestamp&lt;UL&gt;&lt;LI&gt;There is no direct way, to convert it to a timestamp as you mentioned already.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!! Kindly upvote if this helps!!!&lt;/P&gt;</description>
    <pubDate>Tue, 27 Jun 2023 06:19:32 GMT</pubDate>
    <dc:creator>VatsalJagani</dc:creator>
    <dc:date>2023-06-27T06:19:32Z</dc:date>
    <item>
      <title>Can I use epoch as timestamp in DBConnect?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-use-epoch-as-timestamp-in-DBConnect/m-p/647560#M110115</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;struggling with this for a while.&lt;/P&gt;
&lt;P&gt;I have an epoch time value (10 digit NUMBER) that I want to use as both rising column and timestamp for the event.&lt;/P&gt;
&lt;P&gt;The first works fine , but getting it to use this for the event timestamp not.&lt;/P&gt;
&lt;P&gt;I know about the workaround of&amp;nbsp;timestamp'1970-01-01 00:00:00' + ( "&amp;lt;my_field&amp;gt;" /86400 ) as eventTime,&lt;/P&gt;
&lt;P&gt;but preferably I do not ingest an extra field if it is not really necessary.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there is no config I can get to work for the timestamp.&lt;/P&gt;
&lt;P&gt;from the Java DateTimeFormatter it appears not possible, but just want to ask out here if anyone has ffound something&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;sources:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/DBX/3.13.0/DeployDBX/Troubleshooting" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/DBX/3.13.0/DeployDBX/Troubleshooting&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have also tried using props.conf,&lt;/P&gt;
&lt;PRE&gt;[mysourcetype ]
SHOULD_LINEMERGE=true
NO_BINARY_CHECK=true
TIME_FORMAT=%s
TIME_PREFIX=my_field=&lt;/PRE&gt;
&lt;P&gt;but it doesnt even reach this part and errors out earlier&lt;/P&gt;
&lt;P&gt;error pattern:&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;2023-06-20&lt;/SPAN&gt; &lt;SPAN class=""&gt;10:27:07.521&lt;/SPAN&gt;&lt;SPAN&gt; +&lt;/SPAN&gt;&lt;SPAN class=""&gt;0200&lt;/SPAN&gt; &lt;SPAN class=""&gt;Trace-Id=940a0c4d-8c64-44d7-a948-39fd6e9b7417&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;Scheduled-Job-Executor-5&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;ERROR&lt;/SPAN&gt; &lt;SPAN class=""&gt;org.easybatch.core.job.BatchJob&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Unable&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;process&lt;/SPAN&gt; &lt;SPAN class=""&gt;Record:&lt;/SPAN&gt;&lt;SPAN&gt; {&lt;/SPAN&gt;&lt;SPAN class=""&gt;header=&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;number=1&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;source=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;SHE170U-&lt;SPAN class=""&gt;JOURNEY&lt;/SPAN&gt;_TRACKER&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;creationDate=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Tue&lt;/SPAN&gt; &lt;SPAN class=""&gt;Jun&lt;/SPAN&gt; &lt;SPAN class=""&gt;20&lt;/SPAN&gt; &lt;SPAN class=""&gt;10:27:07&lt;/SPAN&gt; &lt;SPAN class=""&gt;CEST&lt;/SPAN&gt; &lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&lt;SPAN&gt;"], &lt;/SPAN&gt;&lt;SPAN class=""&gt;payload=&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;HikariProxyResultSet@2091779680&lt;/SPAN&gt; &lt;SPAN class=""&gt;wrapping&lt;/SPAN&gt; &lt;SPAN class=""&gt;oracle.jdbc.driver.ForwardOnlyResultSet@4f527ef2&lt;/SPAN&gt;&lt;SPAN&gt;]} &lt;/SPAN&gt;&lt;SPAN class=""&gt;java.time.format.DateTimeParseException:&lt;/SPAN&gt; &lt;FONT color="#FF0000"&gt;&lt;SPAN class=""&gt;Text&lt;/SPAN&gt;&lt;SPAN&gt; '&lt;/SPAN&gt;&lt;SPAN class=""&gt;1687249036&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class=""&gt;could&lt;/SPAN&gt; &lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;be&lt;/SPAN&gt; &lt;SPAN class=""&gt;parsed&lt;/SPAN&gt; &lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;index&lt;/SPAN&gt; &lt;SPAN class=""&gt;0&lt;/SPAN&gt; &lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;java.base/java.time.format.DateTimeFormatter.parseResolved0&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;DateTimeFormatter.java:2052&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;)&lt;/FONT&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;java.base/java.time.format.DateTimeFormatter.parse&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;DateTimeFormatter.java:1880&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;com.splunk.dbx.server.dbinput.task.processors.ExtractIndexingTimeProcessor.extractTimestampFromString&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;ExtractIndexingTimeProcessor.java:112&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;com.splunk.dbx.server.dbinput.task.processors.ExtractIndexingTimeProcessor.extractTimestamp&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;ExtractIndexingTimeProcessor.java:92&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;com.splunk.dbx.server.dbinput.task.processors.ExtractIndexingTimeProcessor.processRecord&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;ExtractIndexingTimeProcessor.java:46&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;org.easybatch.core.processor.CompositeRecordProcessor.processRecord&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;CompositeRecordProcessor.java:61&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;org.easybatch.core.job.BatchJob.processRecord&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;BatchJob.java:209&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;org.easybatch.core.job.BatchJob.readAndProcessBatch&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;BatchJob.java:178&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;org.easybatch.core.job.BatchJob.call&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;BatchJob.java:101&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;com.splunk.dbx.server.api.service.conf.impl.InputServiceImpl.runTask&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;InputServiceImpl.java:298&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;com.splunk.dbx.server.api.resource.InputResource.lambda$runInput$1&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;InputResource.java:162&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;com.splunk.dbx.logging.MdcTaskDecorator.run&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;MdcTaskDecorator.java:23&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;java.base/java.util.concurrent.Executors$RunnableAdapter.call&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;Executors.java:539&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;java.base/java.util.concurrent.FutureTask.run&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;FutureTask.java:264&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;java.base/java.util.concurrent.ThreadPoolExecutor.runWorker&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;ThreadPoolExecutor&lt;/SPAN&gt;.java:1136&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;java.base/java.util.concurrent.ThreadPoolExecutor$Worker.run&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;ThreadPoolExecutor.java:635&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;java.base/java.lang.Thread.run&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;Thread.java:833)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 13:36:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-use-epoch-as-timestamp-in-DBConnect/m-p/647560#M110115</guid>
      <dc:creator>wmuselle</dc:creator>
      <dc:date>2023-06-20T13:36:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can I use epoch as timestamp in DBConnect?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-use-epoch-as-timestamp-in-DBConnect/m-p/648294#M110219</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/45250"&gt;@wmuselle&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;For raising column&lt;UL&gt;&lt;LI&gt;You should be able to use that column as a raising column without any change&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;For timestamp&lt;UL&gt;&lt;LI&gt;There is no direct way, to convert it to a timestamp as you mentioned already.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!! Kindly upvote if this helps!!!&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 06:19:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-use-epoch-as-timestamp-in-DBConnect/m-p/648294#M110219</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2023-06-27T06:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can I use epoch as timestamp in DBConnect?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-use-epoch-as-timestamp-in-DBConnect/m-p/648296#M110220</link>
      <description>&lt;UL&gt;&lt;LI&gt;For timestamp&lt;UL&gt;&lt;LI&gt;There is no direct way, to convert it to a timestamp as you mentioned already.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;that's my point , I don't understand why there is no support for epoch timestamps in DB connect&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 06:32:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-use-epoch-as-timestamp-in-DBConnect/m-p/648296#M110220</guid>
      <dc:creator>wmuselle</dc:creator>
      <dc:date>2023-06-27T06:32:53Z</dc:date>
    </item>
  </channel>
</rss>

