All Apps and Add-ons

Why can't I select field's alias name as 'rising column' in DBConnect 3.x?

jawaharas
Motivator

The Splunk DB Connect app doesn't allow to select the custom field with alias name (EPOCH_TIMESTAMP) as 'Rising Column'. Any guidance will be helpful. Thanks.

DBConnect SQL:

SELECT 
    OS_USERNAME,
    DBUSERNAME,
    CLIENT_PROGRAM_NAME, 
    EVENT_TIMESTAMP,
    (CAST(EVENT_TIMESTAMP AS DATE) - DATE '1970-01-01')*24*60*60*1000 + MOD( EXTRACT( SECOND FROM EVENT_TIMESTAMP ), 1 ) * 1000 AS EPOCH_TIMESTAMP,
FROM sys.UNIFIED_AUDIT_TRAIL
WHERE EPOCH_TIMESTAMP > ?
ORDER BY EPOCH_TIMESTAMP ASC
0 Karma
1 Solution

FrankVl
Ultra Champion

Try it like this:

SELECT 
     OS_USERNAME,
     DBUSERNAME,
     CLIENT_PROGRAM_NAME, 
     EVENT_TIMESTAMP,
     (CAST(EVENT_TIMESTAMP AS DATE) - DATE '1970-01-01')*24*60*60*1000 + MOD( EXTRACT( SECOND FROM EVENT_TIMESTAMP ), 1 ) * 1000 AS EPOCH_TIMESTAMP,
 FROM sys.UNIFIED_AUDIT_TRAIL
 WHERE  (CAST(EVENT_TIMESTAMP AS DATE) - DATE '1970-01-01')*24*60*60*1000 + MOD( EXTRACT( SECOND FROM EVENT_TIMESTAMP ), 1 ) * 1000 > ?
 ORDER BY EPOCH_TIMESTAMP ASC

View solution in original post

FrankVl
Ultra Champion

Try it like this:

SELECT 
     OS_USERNAME,
     DBUSERNAME,
     CLIENT_PROGRAM_NAME, 
     EVENT_TIMESTAMP,
     (CAST(EVENT_TIMESTAMP AS DATE) - DATE '1970-01-01')*24*60*60*1000 + MOD( EXTRACT( SECOND FROM EVENT_TIMESTAMP ), 1 ) * 1000 AS EPOCH_TIMESTAMP,
 FROM sys.UNIFIED_AUDIT_TRAIL
 WHERE  (CAST(EVENT_TIMESTAMP AS DATE) - DATE '1970-01-01')*24*60*60*1000 + MOD( EXTRACT( SECOND FROM EVENT_TIMESTAMP ), 1 ) * 1000 > ?
 ORDER BY EPOCH_TIMESTAMP ASC

jawaharas
Motivator

Perfect..! Thank you so much @FrankVI

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...