All Apps and Add-ons
Highlighted

map search with dbxquery is not returning any Result

New Member

Hey there,

I have stumbled upon an issue where my below dbxquery map search is not yielding any results.
My intention is to pass a list of student_id values derived from my initial search to the dbxquery and get a list of state with their counts.

index="syslog" TERM(AUS)
| table studentid
| map search="dbxquery query=\"select distinct address
state, count(*)
FROM stud.common.details WHERE site='$studentid$' group by addressstate\" connection=Student"

0 Karma
Highlighted

Re: map search with dbxquery is not returning any Result

SplunkTrust
SplunkTrust

@manunairadavakkat

try by adding |.

index="syslog" TERM(AUS)
| table student_id
| map search="| dbxquery query=\"select distinct address_state, count(*)
FROM stud.common.details WHERE site='$student_id$' group by address_state\" connection=Student"
0 Karma
Highlighted

Re: map search with dbxquery is not returning any Result

New Member

@kamlesh_vaghela
Tried the below query, but no results being displayed, only displays count of events.

index="syslog" TERM(AUS)
| table studentid
| map search="| dbxquery connection=Student query=\"select distinct address
state, count(*)
FROM stud.common.details WHERE group by addressstate\" | site='$studentid$' "

0 Karma
Highlighted

Re: map search with dbxquery is not returning any Result

SplunkTrust
SplunkTrust

@manunairadavakkat

What are your required columns?

0 Karma
Highlighted

Re: map search with dbxquery is not returning any Result

New Member

@kamleshvaghela
Required columns : address
state, count(*)

It should include all those studentid from the earlier search ----
index="syslog" TERM(AUS)
| table student
id

0 Karma
Highlighted

Re: map search with dbxquery is not returning any Result

SplunkTrust
SplunkTrust

@manunairadavakkat

Can you please try this?

index="syslog" TERM(AUS)
| table student_id
| map search="| dbxquery connection=Student query=\"select distinct address_state, count(*) as count
FROM stud.common.details WHERE group by address_state\" | site='$student_id$' | eval student_id='$student_id$' | table student_id address_state count"
0 Karma
Highlighted

Re: map search with dbxquery is not returning any Result

New Member

@kamlesh_vaghela
It does not give any results.

Only the below count is shown:

21,657 events   (26/07/2019 18:01:01.000 to 26/07/2019 18:16:01.000)

"No results found" message in the result box

0 Karma
Highlighted

Re: map search with dbxquery is not returning any Result

SplunkTrust
SplunkTrust

@manunairadavakkat

Can you please execute below search by passing student_id and check results?

| dbxquery connection=Student query="select distinct addressstate, count(*) as count
FROM stud.common.details WHERE group by address
state" | site='$studentid$' | eval studentid='$studentid$' | table studentid address_state count

0 Karma
Highlighted

Re: map search with dbxquery is not returning any Result

New Member

@kamlesh_vaghela

Ran the query directly, it shows 117 results.
When running the above query as well, it shows event count as 117, but no results are displayed

0 Karma
Highlighted

Re: map search with dbxquery is not returning any Result

SplunkTrust
SplunkTrust

is it possible to share a screenshot?

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.