Splunk Search

continuously DB query with overcome short date format

OBsecurity
Explorer

Hello,
im trying querying HIVE table via 'rising' mode.
query must contain certain timestamp_1 column (otherwise no results are back - massive data)
and must be rising method since results must be real-time.
Unfortunately timestamp column represented with yyyy-MM-dd format only (e.g 2018-01-04) - therefore cannot query real-time.
Table also include bigint date column, i was trying:
1. casting it to readable timestamp - no good.
2. using bigint column as 'rising' - no good.
all of this because timestamp_1 wasnt part of where clause.

  • im using splunk dbx.

any ideas? work arounds?

thanks!

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...