All Apps and Add-ons

After migrating from Splunk DB Connect version 1 to version 2, why does the app handle date time differently than the previous version?

groland
Explorer

Hi everyone,

When I used Splunk DB Connect v1 on MS SQL, I was able to something like that (very simplified):

| dbquery mssql "SELECT GETDATE() AS getdate" | eval _time = getdate | timechart count

But with Splunk DB Connect v2, the datetime is output as string and wasn't recognized as a timestamp, so this doesn't work anymore:

| dbxquery connection=mssql query="SELECT GETDATE() AS getdate" | eval _time = getdate | timechart count

The workaround is to convert the date to timestamp before using it in the timechart:

| dbxquery connection=mssql shortnames=t query="SELECT GETDATE() AS getdate" | eval getdate = strptime(getdate, "%Y-%m-%d %H:%M:%S.%3Q") | eval _time = getdate | timechart count

Is this a desired feature or an issue on my side?

Thanks!

0 Karma
1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

Hi,

This is intentional. The documentation under "Choose Column" in http://docs.splunk.com/Documentation/DBX/3.0.0/DeployDBX/Createandmanagedatabaseinputs#Set_parameter... covers the current behavior for this feature.

View solution in original post

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Hi,

This is intentional. The documentation under "Choose Column" in http://docs.splunk.com/Documentation/DBX/3.0.0/DeployDBX/Createandmanagedatabaseinputs#Set_parameter... covers the current behavior for this feature.

0 Karma

groland
Explorer

Hi,

Thanks for the answer. Maybe things have changed now with DBX 3.0.0 (I haven't tested).
For the documentation, is seem talking about the inputs and on my side, I've an issue with the dbxquery so those parameters aren't available (because it's not indexation).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...