<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk DB Connect 1: Where do I put the token name in a dbquery search string for a chart drilldown? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DB-Connect-1-Where-do-I-put-the-token-name-in-a-dbquery/m-p/171213#M186412</link>
    <description>&lt;P&gt;Yes. Thank you verymuch. I have already got it. I have tried like that same process&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jun 2015 12:11:05 GMT</pubDate>
    <dc:creator>kavyaa</dc:creator>
    <dc:date>2015-06-24T12:11:05Z</dc:date>
    <item>
      <title>Splunk DB Connect 1: Where do I put the token name in a dbquery search string for a chart drilldown?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DB-Connect-1-Where-do-I-put-the-token-name-in-a-dbquery/m-p/171210#M186409</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm using Splunk 6.2.3 and DB Connect 1. I have connected to an Oracle database. I have applied an input drilldown on a chart, but it is showing &lt;CODE&gt;"error in dbquery command". this command must be in first search"&lt;/CODE&gt;. Please help me and share any document for this.&lt;/P&gt;

&lt;P&gt;Thanks in advance,&lt;BR /&gt;
A.kavya.&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/417i5CC7E172C8241334/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2015 07:03:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DB-Connect-1-Where-do-I-put-the-token-name-in-a-dbquery/m-p/171210#M186409</guid>
      <dc:creator>kavyaa</dc:creator>
      <dc:date>2015-06-24T07:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect 1: Where do I put the token name in a dbquery search string for a chart drilldown?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DB-Connect-1-Where-do-I-put-the-token-name-in-a-dbquery/m-p/171211#M186410</link>
      <description>&lt;P&gt;dbquery command must exist as the first word in the query. you can use token fields inside the query or later part.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2015 07:07:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DB-Connect-1-Where-do-I-put-the-token-name-in-a-dbquery/m-p/171211#M186410</guid>
      <dc:creator>srinathd</dc:creator>
      <dc:date>2015-06-24T07:07:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect 1: Where do I put the token name in a dbquery search string for a chart drilldown?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DB-Connect-1-Where-do-I-put-the-token-name-in-a-dbquery/m-p/171212#M186411</link>
      <description>&lt;P&gt;try like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | dbquery Oracle limit=1000 "SELECT DISTINCTn EFZ_VIEW_DWT_CBS_GL_BAL.COMPANY_CODE as Subsidiary,n EFZ_VIEW_DWT_CBS_ ...."|eval your_field_name="$field1$"|where your_filter_field=your_field_name|....
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 24 Jun 2015 11:02:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DB-Connect-1-Where-do-I-put-the-token-name-in-a-dbquery/m-p/171212#M186411</guid>
      <dc:creator>fdi01</dc:creator>
      <dc:date>2015-06-24T11:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect 1: Where do I put the token name in a dbquery search string for a chart drilldown?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DB-Connect-1-Where-do-I-put-the-token-name-in-a-dbquery/m-p/171213#M186412</link>
      <description>&lt;P&gt;Yes. Thank you verymuch. I have already got it. I have tried like that same process&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2015 12:11:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DB-Connect-1-Where-do-I-put-the-token-name-in-a-dbquery/m-p/171213#M186412</guid>
      <dc:creator>kavyaa</dc:creator>
      <dc:date>2015-06-24T12:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect 1: Where do I put the token name in a dbquery search string for a chart drilldown?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DB-Connect-1-Where-do-I-put-the-token-name-in-a-dbquery/m-p/171214#M186413</link>
      <description>&lt;P&gt;i happy for you.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2015 12:50:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DB-Connect-1-Where-do-I-put-the-token-name-in-a-dbquery/m-p/171214#M186413</guid>
      <dc:creator>fdi01</dc:creator>
      <dc:date>2015-06-24T12:50:56Z</dc:date>
    </item>
  </channel>
</rss>

