Splunk Search

continuously DB query with overcome short date format

OBsecurity
Explorer

Hello,
im trying querying HIVE table via 'rising' mode.
query must contain certain timestamp_1 column (otherwise no results are back - massive data)
and must be rising method since results must be real-time.
Unfortunately timestamp column represented with yyyy-MM-dd format only (e.g 2018-01-04) - therefore cannot query real-time.
Table also include bigint date column, i was trying:
1. casting it to readable timestamp - no good.
2. using bigint column as 'rising' - no good.
all of this because timestamp_1 wasnt part of where clause.

  • im using splunk dbx.

any ideas? work arounds?

thanks!

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...