All Apps and Add-ons

Why can't I select field's alias name as 'rising column' in DBConnect 3.x?

jawaharas
Motivator

The Splunk DB Connect app doesn't allow to select the custom field with alias name (EPOCH_TIMESTAMP) as 'Rising Column'. Any guidance will be helpful. Thanks.

DBConnect SQL:

SELECT 
    OS_USERNAME,
    DBUSERNAME,
    CLIENT_PROGRAM_NAME, 
    EVENT_TIMESTAMP,
    (CAST(EVENT_TIMESTAMP AS DATE) - DATE '1970-01-01')*24*60*60*1000 + MOD( EXTRACT( SECOND FROM EVENT_TIMESTAMP ), 1 ) * 1000 AS EPOCH_TIMESTAMP,
FROM sys.UNIFIED_AUDIT_TRAIL
WHERE EPOCH_TIMESTAMP > ?
ORDER BY EPOCH_TIMESTAMP ASC
0 Karma
1 Solution

FrankVl
Ultra Champion

Try it like this:

SELECT 
     OS_USERNAME,
     DBUSERNAME,
     CLIENT_PROGRAM_NAME, 
     EVENT_TIMESTAMP,
     (CAST(EVENT_TIMESTAMP AS DATE) - DATE '1970-01-01')*24*60*60*1000 + MOD( EXTRACT( SECOND FROM EVENT_TIMESTAMP ), 1 ) * 1000 AS EPOCH_TIMESTAMP,
 FROM sys.UNIFIED_AUDIT_TRAIL
 WHERE  (CAST(EVENT_TIMESTAMP AS DATE) - DATE '1970-01-01')*24*60*60*1000 + MOD( EXTRACT( SECOND FROM EVENT_TIMESTAMP ), 1 ) * 1000 > ?
 ORDER BY EPOCH_TIMESTAMP ASC

View solution in original post

FrankVl
Ultra Champion

Try it like this:

SELECT 
     OS_USERNAME,
     DBUSERNAME,
     CLIENT_PROGRAM_NAME, 
     EVENT_TIMESTAMP,
     (CAST(EVENT_TIMESTAMP AS DATE) - DATE '1970-01-01')*24*60*60*1000 + MOD( EXTRACT( SECOND FROM EVENT_TIMESTAMP ), 1 ) * 1000 AS EPOCH_TIMESTAMP,
 FROM sys.UNIFIED_AUDIT_TRAIL
 WHERE  (CAST(EVENT_TIMESTAMP AS DATE) - DATE '1970-01-01')*24*60*60*1000 + MOD( EXTRACT( SECOND FROM EVENT_TIMESTAMP ), 1 ) * 1000 > ?
 ORDER BY EPOCH_TIMESTAMP ASC

jawaharas
Motivator

Perfect..! Thank you so much @FrankVI

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...