Getting Data In

Is it possible to get concat fields through db connect?

ragonfly
New Member

Hello. I need help with DB data input.

Among the fields of the mariadb table, the field related to time is divided into two.

Both fields are of type varchar.

 

1) The date field stores today's date. ex) 2022215

2) The time field stores the time. Leading zeros are omitted.

ex) 110203000 (hhmmssSSS)

For time fields, leading zeros are omitted.  In the case of 00:02:03, it becomes as follows.

ex) 203000 

As a side note, I know these configurations aren't common, I didn't create them.

In the above situation, to get data through the rising column, the query is structured as follows.

 

select concat(date,lpad(time,'9','0')) as time from ~~~ where time > 1

 

If i execute a query on the db connect setting screen, data is imported normally.

However, once the setup is complete and the query is run on a schedule, the data will not be indexed.

In db connect, if data is artificially processed through a query, can't I get data?

 

thank you.

Labels (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

* You have to add a question mark (?) with where condition and DB Connect would replace the checkpoint value of rising column there. (Please read the instruction in the UI just below the rising column option.)

* You can apply it on artificially generated columns. But last time when I had a similar situation I couldn't able to do it through UI. So I had to create input start in db_inputs.conf from the backend.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...