All Apps and Add-ons

How does Data Typing work in Splunk and Hunk?

ddrillic
Ultra Champion

I wonder about data typing in Splunk/Hunk.

We had the case of exporting ssns to a csv file -
In this case the ssn is defined as String in Hive, but since it's comprised almost exclusively of digits, it's being treated as a number within Hunk.

Is this the expected behavior?

Tags (4)
0 Karma
1 Solution

Ledion_Bitincka
Splunk Employee
Splunk Employee

Not sure exactly what you mean about ssn being treated as numbers in Splunk/Hunk, can you please elaborate on what issues is this causing? SPL is loosely typed, ie each command will convert/cast field values into the type that it needs.

View solution in original post

0 Karma

Ledion_Bitincka
Splunk Employee
Splunk Employee

Not sure exactly what you mean about ssn being treated as numbers in Splunk/Hunk, can you please elaborate on what issues is this causing? SPL is loosely typed, ie each command will convert/cast field values into the type that it needs.

0 Karma

ddrillic
Ultra Champion

Thank you Ledion. In Exporting SSNs to a CSV file trims leading zeros

we spoke about the SSN issue. The thing is that with Hunk when using Hive, we specify the data type and Splunk defines the data type ignoring the Hive data type. It leads to a situation, where the SSN values are being modified when exported out, or being treated as numbers within Splunk.

Does it make sense?

0 Karma

ddrillic
Ultra Champion

Any thoughts, by any chance?

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...