Splunk Search

continuously DB query with overcome short date format

OBsecurity
Explorer

Hello,
im trying querying HIVE table via 'rising' mode.
query must contain certain timestamp_1 column (otherwise no results are back - massive data)
and must be rising method since results must be real-time.
Unfortunately timestamp column represented with yyyy-MM-dd format only (e.g 2018-01-04) - therefore cannot query real-time.
Table also include bigint date column, i was trying:
1. casting it to readable timestamp - no good.
2. using bigint column as 'rising' - no good.
all of this because timestamp_1 wasnt part of where clause.

  • im using splunk dbx.

any ideas? work arounds?

thanks!

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...