Splunk Search

Pivot Issue

ShaneNewman
Motivator

I have to use a root search in a pivot due to needing to join another data type. Is there a way to get _time to extract as Time? I have setup an eval in the pivot to extract the _time field but it wants to define _time as a string. Is there anyway to fix this?

Tags (3)
1 Solution

ShaneNewman
Motivator

Turns out there is no way to do this using the Pivot model at this time.

View solution in original post

ShaneNewman
Motivator

Turns out there is no way to do this using the Pivot model at this time.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...