<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic sql query to splunk query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/sql-query-to-splunk-query/m-p/455381#M128757</link>
    <description>&lt;P&gt;How I can Change this sql query to splunk query, I tried in different way but It is not giving proper result please help me&lt;/P&gt;

&lt;P&gt;Select sys.name as 'CName', count(ucs.RID) [Update], sys.Workgr as 'Domain'&lt;BR /&gt;
From  Update_CS ucs&lt;BR /&gt;
JOIN System sys on sys. RID = ucs. RID&lt;BR /&gt;
JOIN  UpdateIn ui on ucs.CID = ui.CID&lt;BR /&gt;
Where ucs. RID IN(Select RID from FullCollection where Coll_ID = '1010') AND&lt;BR /&gt;
UCS.CID IN(select TCID from SMS_CIR&lt;BR /&gt;
where FCID = '100200') AND UCS.status in ('0','2')&lt;BR /&gt;
GROUP BY sys.name, sys. Workgr&lt;BR /&gt;
ORDER BY 'CName' ASC&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 01:48:57 GMT</pubDate>
    <dc:creator>deeptha1992</dc:creator>
    <dc:date>2020-09-30T01:48:57Z</dc:date>
    <item>
      <title>sql query to splunk query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sql-query-to-splunk-query/m-p/455381#M128757</link>
      <description>&lt;P&gt;How I can Change this sql query to splunk query, I tried in different way but It is not giving proper result please help me&lt;/P&gt;

&lt;P&gt;Select sys.name as 'CName', count(ucs.RID) [Update], sys.Workgr as 'Domain'&lt;BR /&gt;
From  Update_CS ucs&lt;BR /&gt;
JOIN System sys on sys. RID = ucs. RID&lt;BR /&gt;
JOIN  UpdateIn ui on ucs.CID = ui.CID&lt;BR /&gt;
Where ucs. RID IN(Select RID from FullCollection where Coll_ID = '1010') AND&lt;BR /&gt;
UCS.CID IN(select TCID from SMS_CIR&lt;BR /&gt;
where FCID = '100200') AND UCS.status in ('0','2')&lt;BR /&gt;
GROUP BY sys.name, sys. Workgr&lt;BR /&gt;
ORDER BY 'CName' ASC&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:48:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sql-query-to-splunk-query/m-p/455381#M128757</guid>
      <dc:creator>deeptha1992</dc:creator>
      <dc:date>2020-09-30T01:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: sql query to splunk query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sql-query-to-splunk-query/m-p/455382#M128758</link>
      <description>&lt;P&gt;Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| dbxquery query="Select sys.name as 'CName', count(ucs.RID) [Update], sys.Workgr as 'Domain'
 From Update_CS ucs
 JOIN System sys on sys. RID = ucs. RID
 JOIN UpdateIn ui on ucs.CID = ui.CID
 Where ucs. RID IN(Select RID from FullCollection where Coll_ID = '1010') AND
 UCS.CID IN(select TCID from SMS_CIR
 where FCID = '100200') AND UCS.status in ('0','2')
 GROUP BY sys.name, sys. Workgr
 ORDER BY 'CName' ASC" connection="&amp;lt;not_selected&amp;gt;" 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 21 Aug 2019 11:13:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sql-query-to-splunk-query/m-p/455382#M128758</guid>
      <dc:creator>Azeemering</dc:creator>
      <dc:date>2019-08-21T11:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: sql query to splunk query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sql-query-to-splunk-query/m-p/455383#M128759</link>
      <description>&lt;P&gt;Thanks.. But i need to convert this to SPL query. I have onboarded the table through splunk db connect. I need to create dashboard as like this query provided. want to know how to write a search query from this given sql query.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 11:42:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sql-query-to-splunk-query/m-p/455383#M128759</guid>
      <dc:creator>deeptha1992</dc:creator>
      <dc:date>2019-08-21T11:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: sql query to splunk query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sql-query-to-splunk-query/m-p/455384#M128760</link>
      <description>&lt;P&gt;@deeptha1992 &lt;/P&gt;

&lt;P&gt;Please check below link and let us know if you require any further assistance in SPL design. &lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.5.2/SearchReference/SQLtoSplunk"&gt;https://docs.splunk.com/Documentation/Splunk/6.5.2/SearchReference/SQLtoSplunk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 12:44:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sql-query-to-splunk-query/m-p/455384#M128760</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2019-08-21T12:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: sql query to splunk query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sql-query-to-splunk-query/m-p/455385#M128761</link>
      <description>&lt;P&gt;Please try with below syntax to get the SQL query working in splunk: &lt;/P&gt;

&lt;P&gt;|  dbxquery connection= [fetchsize=] [maxrows=] [timeout=] [shortnames=] query= OR procedure= [params=] &lt;/P&gt;

&lt;P&gt;For more information: Please see the splunk documentation. &lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/DBX/3.1.4/DeployDBX/Commands"&gt;https://docs.splunk.com/Documentation/DBX/3.1.4/DeployDBX/Commands&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 14:36:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sql-query-to-splunk-query/m-p/455385#M128761</guid>
      <dc:creator>harish_l</dc:creator>
      <dc:date>2019-08-21T14:36:18Z</dc:date>
    </item>
  </channel>
</rss>

