Getting Data In

Splunk DB Connect 1: How to parse a dbquery search string to convert Unix timestamps to a readable format and create a timechart?

jtracy
Engager

I have a string like this;

| dbquery MYDATABASE "Select trunc(ph.x_rqst_date) bp_date,count(ph.objid) bpcount,ph.x_ics_rcode _code,
 X_AUTH_RESPONSE paymen_code,ph.x_payment_type type
 from x_program_purch_hdr ph    
 where x_rqst_type='CREDITCARD_PURCH'
 AND ph.x_payment_type IN ('ENROLLMENT','RECURRING')
 and ph.x_rqst_date >= Trunc(sysdate)-1
 and ph.x_rqst_date < Trunc(sysdate)
 GROUP BY trunc(ph.x_rqst_date),ph.x_ics_rcode,X_AUTH_RESPONSE,ph.x_payment_type"

But I cannot parse this query with things like |timechart count by code limit=25. Am I missing something? I want to convert all the unreadable unix timestamps to readable, and make a timechart.

0 Karma
1 Solution

justinatpnnl
Communicator

Timechart relies on having a _time field for your data. If your date field is already in epoch format, just rename the column with the date to _time:

| rename bp_date as _time

Then try adding your timechart after that. The alternative would be to name the column within your query:

Select trunc(ph.x_rqst_date) _time

View solution in original post

justinatpnnl
Communicator

Timechart relies on having a _time field for your data. If your date field is already in epoch format, just rename the column with the date to _time:

| rename bp_date as _time

Then try adding your timechart after that. The alternative would be to name the column within your query:

Select trunc(ph.x_rqst_date) _time

jtracy
Engager

This was it! Thank you kind sir.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...