Getting Data In

What is the difference between the dbinspect command and "_bkt"?

realsplunk
Builder

Hello guys,

Could you let me know the difference in terms of buckets between :

| dbinspect *search* and *search* | eval bkt=_bkt | table bkt ?
It looks like dbinspect returns more results and with a wider span. My aim is to remove buckets according to a specific search and timeframe.

Thanks.

0 Karma
1 Solution

realsplunk
Builder

Solved by support :

dbinspect take it data from the metadata
_bkt from from the search process.

the metadata can be update when we search but you
will search on your old generation id.

View solution in original post

0 Karma

realsplunk
Builder

Solved by support :

dbinspect take it data from the metadata
_bkt from from the search process.

the metadata can be update when we search but you
will search on your old generation id.

View solution in original post

0 Karma

gjanders
SplunkTrust
SplunkTrust

Can you accept your answer please? That will make this clear that you've answered your own question

realsplunk
Builder

"We're sorry, but you cannot vote on your own post." 🙂

0 Karma

gjanders
SplunkTrust
SplunkTrust

Correct, but as per How to earn Karma you will get some points and you can up-vote anyone else's posts 🙂

0 Karma

gjanders
SplunkTrust
SplunkTrust

What are you trying to achieve by removing buckets?
You've also only posted a single search query mentioning dbinspect, dbinspect lists buckets on a per-index basis including replicated buckets.

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!