Splunk Search

Stats Max issue

willadams
Contributor

I have a query that I am running using dbxquery for specific reasons. Anyway I have run into an interesting issue that I can't seem to put my finger on

My First Query is through SPLUNK 7.2.3 with DBConnect 2.1.4

| dbxquery query="SELECT * FROM \"AppList\".\"dbo\".\"SPLNK_MyTable\"" connection="ApplicationX" wrap=t 
| fields - _raw _time 
| rename "Computer name" AS "name" 
| rename "App File used" AS "App File" 
| rename "Last check-in (GMT)" AS "Last Check In" 
| rename "App Distri" AS "App Version" 
| rename "APPLICATION STATUS" AS "status" 
| eval LastCheckInEpoch=strptime("Last Check In", "%Y-%m-%d %H:%M:%S.%1Q") 
| where (LastCheckInEpoch>= relative_time(now(), "-30d@d") AND LastCheckInEpoch<= now()) 
| stats max(status) as status by name, "App File", "Last Check In", "AppVersion" | eval name=upper(name)

I get results and statistics is happy in his instance.

However running this on SPLUNK 7.2.6 with DBConnect 3.13 I get 0 results. I can't see why. Any suggestions?

Tags (1)
0 Karma

willadams
Contributor

As suggested by to4kawa the where statement looks like it is not working. On checking my strptime command, I noted that I had %Y-%m-%d %H:%M:%S.%1Q but on adjusting this to %Y-%m-%d %H:%M:%S.%3Q, this seems to have done the trick. I also noted that one of my renames had a lower case instead of an upper case which caused it to break as well.

0 Karma

willadams
Contributor

I also had to remove "wrap=t"

0 Karma
Get Updates on the Splunk Community!

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...