<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: db connect timestamp conversion in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/db-connect-timestamp-conversion/m-p/96789#M97464</link>
    <description>&lt;P&gt;To use a DB result field as the event time, then do this:&lt;BR /&gt;
    | dbxquery connection=your.db.connection query="SELECT createdAt, name FROM some_table" | eval _time=strptime(createdAt, "%Y-%m-%d %H:%M:%S") | timechart span=7d count by name&lt;BR /&gt;
This assumes date/time fields come back from your DB like 2017-10-16 16:20:00.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Oct 2017 18:14:18 GMT</pubDate>
    <dc:creator>zsteinkamp_splu</dc:creator>
    <dc:date>2017-10-16T18:14:18Z</dc:date>
    <item>
      <title>db connect timestamp conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/db-connect-timestamp-conversion/m-p/96784#M97459</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We are running queries directly in the splunk db connect and not doing an input but the timestamps are getting reformatted and there is no obvious correlation between the two. For example: the query in SQL returns the Update_Time field as 2013-04-10 10:11:50 (yes it is set as a date/time field) but when I run the same query in splunk db connect it returns 1365603110.000. Any ideas how to reformat it?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2013 20:34:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/db-connect-timestamp-conversion/m-p/96784#M97459</guid>
      <dc:creator>aaronkorn</dc:creator>
      <dc:date>2013-04-16T20:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: db connect timestamp conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/db-connect-timestamp-conversion/m-p/96785#M97460</link>
      <description>&lt;P&gt;In Splunk, add:  &lt;CODE&gt;| convert ctime(Update_Time)&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2013 21:32:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/db-connect-timestamp-conversion/m-p/96785#M97460</guid>
      <dc:creator>Dan</dc:creator>
      <dc:date>2013-04-16T21:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: db connect timestamp conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/db-connect-timestamp-conversion/m-p/96786#M97461</link>
      <description>&lt;P&gt;excellent! Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2013 12:20:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/db-connect-timestamp-conversion/m-p/96786#M97461</guid>
      <dc:creator>aaronkorn</dc:creator>
      <dc:date>2013-04-17T12:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: db connect timestamp conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/db-connect-timestamp-conversion/m-p/96787#M97462</link>
      <description>&lt;P&gt;This is helpful, but how do I create a time chart after doing this?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2013 15:28:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/db-connect-timestamp-conversion/m-p/96787#M97462</guid>
      <dc:creator>ihayesjr</dc:creator>
      <dc:date>2013-06-14T15:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: db connect timestamp conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/db-connect-timestamp-conversion/m-p/96788#M97463</link>
      <description>&lt;P&gt;| bucket Update_Time span=2m | stats count by Update_Time&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:05:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/db-connect-timestamp-conversion/m-p/96788#M97463</guid>
      <dc:creator>Dan</dc:creator>
      <dc:date>2020-09-28T14:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: db connect timestamp conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/db-connect-timestamp-conversion/m-p/96789#M97464</link>
      <description>&lt;P&gt;To use a DB result field as the event time, then do this:&lt;BR /&gt;
    | dbxquery connection=your.db.connection query="SELECT createdAt, name FROM some_table" | eval _time=strptime(createdAt, "%Y-%m-%d %H:%M:%S") | timechart span=7d count by name&lt;BR /&gt;
This assumes date/time fields come back from your DB like 2017-10-16 16:20:00.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 18:14:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/db-connect-timestamp-conversion/m-p/96789#M97464</guid>
      <dc:creator>zsteinkamp_splu</dc:creator>
      <dc:date>2017-10-16T18:14:18Z</dc:date>
    </item>
  </channel>
</rss>

