<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with database table name with spaces in map dbxquery search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-database-table-name-with-spaces-in-map-dbxquery/m-p/471139#M132544</link>
    <description>&lt;P&gt;Do not surround the field name or table name with double quotes but with backticks&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   | fields EMPID
   | map search="| dbxquery query=\"select `Employer Name` PR, `Employee Number` EMPID FROM BIA_BA_EUL.`View Employee Helpdesk` WHERE `Employee Number` in ($EMPID$)\" connection=\"EMP-PR\"" 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 04 Sep 2019 14:40:14 GMT</pubDate>
    <dc:creator>thomasroulet</dc:creator>
    <dc:date>2019-09-04T14:40:14Z</dc:date>
    <item>
      <title>Issue with database table name with spaces in map dbxquery search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-database-table-name-with-spaces-in-map-dbxquery/m-p/471137#M132542</link>
      <description>&lt;P&gt;Hi Splunk experts,&lt;/P&gt;

&lt;P&gt;Please help on the below issue.&lt;BR /&gt;
When i am running a query directly with dbxquery, the table name with spaces(View Employee Helpdesk) and column name with spaces  is not creating any issues. I am getting results as expected. &lt;/P&gt;

&lt;P&gt;| dbxquery query="select \"Employee Number\",\"Manager\"&lt;BR /&gt;
FROM&lt;BR /&gt;
BIA_BA_EUL.\"View Employee Helpdesk\" WHERE \"Employee Number\"=('EMP1')" connection="EMP-PR1"&lt;/P&gt;

&lt;P&gt;Whereas, when i am using the same table and cloumn name in map search with dbxquery it is not being recognised and throwing error.&lt;/P&gt;

&lt;P&gt;.........&lt;BR /&gt;
| fields EMPID&lt;BR /&gt;
| map search="| dbxquery query=\"select  \"Employee Number\"&lt;BR /&gt;
FROM BIA_BA_EUL.\"View Employee Helpdesk\" WHERE \"Employee Number\" IN ($EMPID$)\"&lt;BR /&gt;
connection="EMP-PR1""&lt;/P&gt;

&lt;P&gt;Error being thrown:&lt;BR /&gt;
[map]: org.netezza.error.NzSQLException: ERROR: 'select FROM BIA_BA_EUL.View ANALYZE' error ^ found "FROM" (at char 9) expecting an identifier found a keyword&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:03:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-with-database-table-name-with-spaces-in-map-dbxquery/m-p/471137#M132542</guid>
      <dc:creator>manunairadavakk</dc:creator>
      <dc:date>2020-09-30T02:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with database table name with spaces in map dbxquery search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-database-table-name-with-spaces-in-map-dbxquery/m-p/471138#M132543</link>
      <description>&lt;P&gt;I'm still thinking how to resolve this, but if it helps anyone (or helps you), I think the problem is that when you wrap that in map, you are effectively removing one layer of escaping.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| map search="| dbxquery query=\"select \"Employee Number\"
FROM BIA_BA_EUL.\"View Employee Helpdesk\" WHERE \"Employee Number\" IN ($EMPID$)\"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;turns into &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;dbxquery query="select "Employee Number"
FROM BIA_BA_EUL."View Employee Helpdesk" WHERE "Employee Number" IN ($EMPID$)"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is there a reason you can't use dbxlookup instead of map+dbxquery?  It should not require the double-escaping shenanigans, and bonus it should be far faster too!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 14:37:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-with-database-table-name-with-spaces-in-map-dbxquery/m-p/471138#M132543</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2019-09-04T14:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with database table name with spaces in map dbxquery search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-database-table-name-with-spaces-in-map-dbxquery/m-p/471139#M132544</link>
      <description>&lt;P&gt;Do not surround the field name or table name with double quotes but with backticks&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   | fields EMPID
   | map search="| dbxquery query=\"select `Employer Name` PR, `Employee Number` EMPID FROM BIA_BA_EUL.`View Employee Helpdesk` WHERE `Employee Number` in ($EMPID$)\" connection=\"EMP-PR\"" 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 04 Sep 2019 14:40:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-with-database-table-name-with-spaces-in-map-dbxquery/m-p/471139#M132544</guid>
      <dc:creator>thomasroulet</dc:creator>
      <dc:date>2019-09-04T14:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with database table name with spaces in map dbxquery search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-database-table-name-with-spaces-in-map-dbxquery/m-p/471140#M132545</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/171022"&gt;@thomasroulet&lt;/a&gt; &lt;/P&gt;

&lt;P&gt;This will not work because netezza does not recognise backticks, it recognises only double quotes.But somehow in map search it is not being recognised while it is being recognised in ordinary dbxquery.&lt;BR /&gt;
Getting error as below:&lt;/P&gt;

&lt;P&gt;[map]: org.netezza.error.NzSQLException: ERROR: 'select &lt;CODE&gt;Employee Number&lt;/CODE&gt; FROM BIA_BA_EUL.&lt;CODE&gt;View Employee Helpdesk&lt;/CODE&gt; WHERE &lt;CODE&gt;Employee Number&lt;/CODE&gt; IN ('EMP1','EMP2') ANALYZE' error ^ found "`" (at char 24) expecting a keyword&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:03:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-with-database-table-name-with-spaces-in-map-dbxquery/m-p/471140#M132545</guid>
      <dc:creator>manunairadavakk</dc:creator>
      <dc:date>2020-09-30T02:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with database table name with spaces in map dbxquery search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-with-database-table-name-with-spaces-in-map-dbxquery/m-p/471141#M132546</link>
      <description>&lt;P&gt;Ok, escape the backslashes in the query&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    | fields EMPID
    | map search="| dbxquery query=\"select \\\"Employer Name\\\" PR,  \\\"Employee Number\\\" EMPID FROM BIA_BA_EUL.\\\"View Employee Helpdesk\\\" WHERE \\\"Employee Number\\\" in ($EMPID$)\" connection=\"EMP-PR\"" 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 05 Sep 2019 06:59:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-with-database-table-name-with-spaces-in-map-dbxquery/m-p/471141#M132546</guid>
      <dc:creator>thomasroulet</dc:creator>
      <dc:date>2019-09-05T06:59:26Z</dc:date>
    </item>
  </channel>
</rss>

