Splunk Enterprise

How to run this type of queries in splunk

uma2356
Engager

Hi,

I'm having this type of queries, how can i run this in splunk:

SELECT FROM (SELECT rval.,ROWNUM as rn FROM(
select count(*) as count,count(1) over() as tcount, Xipm as location from documentreporting where xidcprofile='IpmApp_1' and XIPM_APP_1_9 is not null group by XIPM_APP_1_9 
rval )WHERE rn >=1 AND rn <= 100
Tags (1)
0 Karma

woodcock
Esteemed Legend

First install DB Connect V3: https://splunkbase.splunk.com/app/2686/
Then run a search like this:

| dbxquery shortnames=t "SELECT * FROM (SELECT rval.*,ROWNUM as rn FROM(select count(*)  as count,count(1) over() as tcount, Xipm  as location  from documentreporting  where xidcprofile='IpmApp_1' and XIPM_APP_1_9 is not null group by XIPM_APP_1_9 rval )WHERE rn >=1 AND rn <= 100"
0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...