Splunk Search

Problem with DB Connect and hive query on float or double fields

wandrilleD
Engager

Hi, I am currently working with Hunk and DB connect, I have connected it to a hive database and after lots of search I finally managed to make it work.

But I'm experiencing a strange problem, when I search for a table which contains some float or double, the search stop with an error:
/!\ No result found
When I search for the exact same query in Hive I'm having the correct number of events.
Searching from the Hiveserver2 logs I found no error, the only error i found is located in the dbx.log:
dbx8845:ERROR:DatabaseQueryCommand - Error while executing command: Error transforming ResultSet: java.sql.SQLException: Illegal conversion

When I search for a float or double casted to String the query execute with no problems, when I query with a hive command such as avg(), sum(), ... (DOUBLE avg(col), avg(DISTINCT col)) it gives me the same error.

I'd like to know where i could find some sources of the dbx library?
So if you guys have any answers that will be great.

Sincerely,
Wandrille

Tags (1)
0 Karma

rdagan_splunk
Splunk Employee
Splunk Employee

Have you tried Hunk with a direct connection to Hive?

Similar to this configuration here: http://docs.splunk.com/Documentation/Hunk/latest/Hunk/ConfigureHivepreprocessor

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...