<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to run query '| dbxquery query ? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-query-dbxquery-query/m-p/631181#M219230</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm quite fresh in splunk and need your help. Trying to combine spl with sql.&lt;/P&gt;
&lt;P&gt;tag 25 is event id same as&amp;nbsp; sql ele.batch_event_id&lt;/P&gt;
&lt;P&gt;I suspect ele.batch_event_id = $25$ is wrong.&lt;/P&gt;
&lt;P&gt;Any idea please &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Error is :&lt;/P&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;Unable to run query '| dbxquery query= "SELECT MIN (ele.process_time) as MIN_PROCESS_time ,MAX (ele.process_time) as MAX_PROCESS_time FROM estar.estar_loopback_events ele, estar.engine_configuration ec WHERE ele.engine_instance = ec.engine_instance AND ele.batch_event_id = $25$ AND process_time BETWEEN TO_DATE('20230215:00:00','YYYYMMDD hh24:mi:ss') and TO_DATE('20230216 12:59:59','YYYYMMDD hh24:mi:ss') " connection='stardb' '.
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Search:&lt;/P&gt;
&lt;P&gt;index=star_linux sourcetype=engine_processed_events 2961= BBHCC-S2PBATCHPOS-BO OR BBHCC-S2PBATCHPOS-B2 OR BBHCC-S2PBATCHPOS-PO OR BBHCC-SOD-IF-Weekday-1 AND 55:GEN_STAR_PACE&lt;BR /&gt;|table 4896,25,55,2961&lt;/P&gt;
&lt;P&gt;| map search="| dbxquery query= \"SELECT MIN (ele.process_time) as MIN_PROCESS_time ,MAX (ele.process_time) as MAX_PROCESS_time&lt;BR /&gt;FROM&lt;BR /&gt;estar.estar_loopback_events ele,&lt;BR /&gt;estar.engine_configuration ec&lt;BR /&gt;WHERE ele.engine_instance = ec.engine_instance&lt;BR /&gt;AND ele.batch_event_id = $25$&lt;BR /&gt;AND process_time BETWEEN TO_DATE('20230215:00:00','YYYYMMDD hh24:mi:ss')&lt;BR /&gt;and TO_DATE('20230216 12:59:59','YYYYMMDD hh24:mi:ss') \" connection='stardb' "&lt;BR /&gt;|table 4896, 25,MIN_PROCESS_time, MAX_PROCESS_time&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 21 Feb 2023 19:52:05 GMT</pubDate>
    <dc:creator>mateusztumi84</dc:creator>
    <dc:date>2023-02-21T19:52:05Z</dc:date>
    <item>
      <title>Unable to run query '| dbxquery query ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-query-dbxquery-query/m-p/631181#M219230</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm quite fresh in splunk and need your help. Trying to combine spl with sql.&lt;/P&gt;
&lt;P&gt;tag 25 is event id same as&amp;nbsp; sql ele.batch_event_id&lt;/P&gt;
&lt;P&gt;I suspect ele.batch_event_id = $25$ is wrong.&lt;/P&gt;
&lt;P&gt;Any idea please &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Error is :&lt;/P&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;Unable to run query '| dbxquery query= "SELECT MIN (ele.process_time) as MIN_PROCESS_time ,MAX (ele.process_time) as MAX_PROCESS_time FROM estar.estar_loopback_events ele, estar.engine_configuration ec WHERE ele.engine_instance = ec.engine_instance AND ele.batch_event_id = $25$ AND process_time BETWEEN TO_DATE('20230215:00:00','YYYYMMDD hh24:mi:ss') and TO_DATE('20230216 12:59:59','YYYYMMDD hh24:mi:ss') " connection='stardb' '.
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Search:&lt;/P&gt;
&lt;P&gt;index=star_linux sourcetype=engine_processed_events 2961= BBHCC-S2PBATCHPOS-BO OR BBHCC-S2PBATCHPOS-B2 OR BBHCC-S2PBATCHPOS-PO OR BBHCC-SOD-IF-Weekday-1 AND 55:GEN_STAR_PACE&lt;BR /&gt;|table 4896,25,55,2961&lt;/P&gt;
&lt;P&gt;| map search="| dbxquery query= \"SELECT MIN (ele.process_time) as MIN_PROCESS_time ,MAX (ele.process_time) as MAX_PROCESS_time&lt;BR /&gt;FROM&lt;BR /&gt;estar.estar_loopback_events ele,&lt;BR /&gt;estar.engine_configuration ec&lt;BR /&gt;WHERE ele.engine_instance = ec.engine_instance&lt;BR /&gt;AND ele.batch_event_id = $25$&lt;BR /&gt;AND process_time BETWEEN TO_DATE('20230215:00:00','YYYYMMDD hh24:mi:ss')&lt;BR /&gt;and TO_DATE('20230216 12:59:59','YYYYMMDD hh24:mi:ss') \" connection='stardb' "&lt;BR /&gt;|table 4896, 25,MIN_PROCESS_time, MAX_PROCESS_time&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 21 Feb 2023 19:52:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-query-dbxquery-query/m-p/631181#M219230</guid>
      <dc:creator>mateusztumi84</dc:creator>
      <dc:date>2023-02-21T19:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run query '| dbxquery query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-query-dbxquery-query/m-p/631191#M219234</link>
      <description>&lt;P&gt;The construct &lt;FONT face="courier new,courier"&gt;$&amp;lt;something&amp;gt;$&lt;/FONT&gt; is valid only with the &lt;FONT face="courier new,courier"&gt;map&lt;/FONT&gt; command or in a dashboard.&amp;nbsp; In every case, however, &lt;FONT face="courier new,courier"&gt;&amp;lt;something&amp;gt;&lt;/FONT&gt; must be a token name or field name rather than a number.&lt;/P&gt;&lt;P&gt;If ele.batch_event_id is a number then use &lt;FONT face="courier new,courier"&gt;ele.batch_event_id=25&lt;/FONT&gt;; otherwise, use &lt;FONT face="courier new,courier"&gt;ele.batch_event_id = "25"&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 13:25:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-query-dbxquery-query/m-p/631191#M219234</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-02-16T13:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run query '| dbxquery query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-query-dbxquery-query/m-p/631533#M219347</link>
      <description>&lt;P&gt;ele.engine_instance is alfanumeric field like &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;6JPK6699UV05FV51&lt;/SPAN&gt;&lt;/SPAN&gt; eg.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 09:15:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-query-dbxquery-query/m-p/631533#M219347</guid>
      <dc:creator>mateusztumi84</dc:creator>
      <dc:date>2023-02-20T09:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run query '| dbxquery query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-query-dbxquery-query/m-p/631535#M219348</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;ele.engine_instance is alfanumeric field like &lt;SPAN class=""&gt;6JPK6699UV05FV51&lt;/SPAN&gt; eg.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 20 Feb 2023 09:16:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-query-dbxquery-query/m-p/631535#M219348</guid>
      <dc:creator>mateusztumi84</dc:creator>
      <dc:date>2023-02-20T09:16:59Z</dc:date>
    </item>
  </channel>
</rss>

