Archive
Highlighted

db connect timestamp conversion

Builder

Hello,

We are running queries directly in the splunk db connect and not doing an input but the timestamps are getting reformatted and there is no obvious correlation between the two. For example: the query in SQL returns the Update_Time field as 2013-04-10 10:11:50 (yes it is set as a date/time field) but when I run the same query in splunk db connect it returns 1365603110.000. Any ideas how to reformat it?

0 Karma
Highlighted

Re: db connect timestamp conversion

Builder

In Splunk, add: | convert ctime(Update_Time)

View solution in original post

Highlighted

Re: db connect timestamp conversion

Builder

excellent! Thank you

0 Karma
Highlighted

Re: db connect timestamp conversion

New Member

This is helpful, but how do I create a time chart after doing this?

0 Karma
Highlighted

Re: db connect timestamp conversion

Builder

| bucket UpdateTime span=2m | stats count by UpdateTime

0 Karma
Highlighted

Re: db connect timestamp conversion

To use a DB result field as the event time, then do this:
| dbxquery connection=your.db.connection query="SELECT createdAt, name FROM some_table" | eval _time=strptime(createdAt, "%Y-%m-%d %H:%M:%S") | timechart span=7d count by name
This assumes date/time fields come back from your DB like 2017-10-16 16:20:00.

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.