Getting Data In

What is the difference between the dbinspect command and "_bkt"?

splunkreal
Motivator

Hello guys,

Could you let me know the difference in terms of buckets between :

| dbinspect *search* and *search* | eval bkt=_bkt | table bkt ?
It looks like dbinspect returns more results and with a wider span. My aim is to remove buckets according to a specific search and timeframe.

Thanks.

* If this helps, please upvote or accept solution 🙂 *
0 Karma
1 Solution

splunkreal
Motivator

Solved by support :

dbinspect take it data from the metadata
_bkt from from the search process.

the metadata can be update when we search but you
will search on your old generation id.

* If this helps, please upvote or accept solution 🙂 *

View solution in original post

0 Karma

splunkreal
Motivator

Solved by support :

dbinspect take it data from the metadata
_bkt from from the search process.

the metadata can be update when we search but you
will search on your old generation id.

* If this helps, please upvote or accept solution 🙂 *
0 Karma

gjanders
SplunkTrust
SplunkTrust

Can you accept your answer please? That will make this clear that you've answered your own question

splunkreal
Motivator

"We're sorry, but you cannot vote on your own post." 🙂

* If this helps, please upvote or accept solution 🙂 *
0 Karma

gjanders
SplunkTrust
SplunkTrust

Correct, but as per How to earn Karma you will get some points and you can up-vote anyone else's posts 🙂

0 Karma

gjanders
SplunkTrust
SplunkTrust

What are you trying to achieve by removing buckets?
You've also only posted a single search query mentioning dbinspect, dbinspect lists buckets on a per-index basis including replicated buckets.

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...