Getting Data In

Is it possible to get concat fields through db connect?

ragonfly
New Member

Hello. I need help with DB data input.

Among the fields of the mariadb table, the field related to time is divided into two.

Both fields are of type varchar.

 

1) The date field stores today's date. ex) 2022215

2) The time field stores the time. Leading zeros are omitted.

ex) 110203000 (hhmmssSSS)

For time fields, leading zeros are omitted.  In the case of 00:02:03, it becomes as follows.

ex) 203000 

As a side note, I know these configurations aren't common, I didn't create them.

In the above situation, to get data through the rising column, the query is structured as follows.

 

select concat(date,lpad(time,'9','0')) as time from ~~~ where time > 1

 

If i execute a query on the db connect setting screen, data is imported normally.

However, once the setup is complete and the query is run on a schedule, the data will not be indexed.

In db connect, if data is artificially processed through a query, can't I get data?

 

thank you.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

* You have to add a question mark (?) with where condition and DB Connect would replace the checkpoint value of rising column there. (Please read the instruction in the UI just below the rising column option.)

* You can apply it on artificially generated columns. But last time when I had a similar situation I couldn't able to do it through UI. So I had to create input start in db_inputs.conf from the backend.

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...