Splunk Search

Splunk DBConnect use the SQL WITH statement

robjackson
Path Finder

Can Splunk DBConnect use the SQL WITH statement?

 

WITH TABLE_BASE AS (
-- this section is the base query and matches the Smart reporting logic

SELECT DISTINCT

The WITH command is not highlighted in red as the other commands.

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@robjackson - Yes you can write the queries with WITH statement.

Color highlighting - It is just that DB Connect is not as smart about SQL queries as Splunk to SPL queries but because DB Connect uses JDBC connector if you have the right drivers installed it should be able to run any correct SQL query.

(I even had a scenario where DB connect was not allowing me to save a SQL query from the inputs page, but I was able to configure the same query from the db_inputs.conf file from the backend.)

So, yes it should run any correct SQL query.

 

I hope this helps!!!

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...