Getting Data In

What is the difference between the dbinspect command and "_bkt"?

splunkreal
Influencer

Hello guys,

Could you let me know the difference in terms of buckets between :

| dbinspect *search* and *search* | eval bkt=_bkt | table bkt ?
It looks like dbinspect returns more results and with a wider span. My aim is to remove buckets according to a specific search and timeframe.

Thanks.

* If this helps, please upvote or accept solution if it solved *
0 Karma
1 Solution

splunkreal
Influencer

Solved by support :

dbinspect take it data from the metadata
_bkt from from the search process.

the metadata can be update when we search but you
will search on your old generation id.

* If this helps, please upvote or accept solution if it solved *

View solution in original post

0 Karma

splunkreal
Influencer

Solved by support :

dbinspect take it data from the metadata
_bkt from from the search process.

the metadata can be update when we search but you
will search on your old generation id.

* If this helps, please upvote or accept solution if it solved *
0 Karma

gjanders
SplunkTrust
SplunkTrust

Can you accept your answer please? That will make this clear that you've answered your own question

splunkreal
Influencer

"We're sorry, but you cannot vote on your own post." 🙂

* If this helps, please upvote or accept solution if it solved *
0 Karma

gjanders
SplunkTrust
SplunkTrust

Correct, but as per How to earn Karma you will get some points and you can up-vote anyone else's posts 🙂

0 Karma

gjanders
SplunkTrust
SplunkTrust

What are you trying to achieve by removing buckets?
You've also only posted a single search query mentioning dbinspect, dbinspect lists buckets on a per-index basis including replicated buckets.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...