All Apps and Add-ons

Splunk DB Connect - Change format to exclude milliseconds in Timestamp or Date as Rising column

manunr5899
New Member

We are using Splunk DB Connect 3.4.0 and have setup a Database input with a timestamp column as Rising column. I can see that Splunk uses milliseconds precision in the rising column field for timestamps, but our DBA is complaining that querying the DB with millisecond precision is causing issues at their end. The database is an Oracle one.

I have tried changing the Rising column to DateTime field but again that having millisecond precision, although in the database I can verify it having till seconds.

Is there anyway I can change the rising column precision to seconds and would that be the right thing to do for rising timestamps/DateTime fields?

Labels (1)
0 Karma

manunr5899
New Member

Is there any solution for this? Can someone please help with the query

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...