I was using dbinpect to calculates the first and last events in my buckets.
In splunk 4.* and 5.*, it was returning 2 fields earliestTime and latestTime as a date in my SH timezone.
But I do not find those fields anymore in 6.*, how to get them ?
Yes, the format of dbinspect changed in 6.*
The time fields were renamed and converted to epoch time.
You can update your searches to use the new fields, or do a simple conversion.
| convert ctime(endEpoch) AS earliestTime
| convert ctime(startEpoch) AS latestTime
View solution in original post
you need to switch:
earliestTime (in formatted time ) became startEpoch (in epoch)
latestTime (in formatted time ) became endEpoch (in epoch)
| convert ctime(endEpoch) AS latestTime | convert ctime(startEpoch) AS earliestTime
gotta get yannK to flip the fields in the convert
startEpoch - The timestamp for the first event in the bucket (the time-edge of the bucket furthest towards the past), in number of seconds from the UNIX epoch.
endEpoch - The timestamp for the last event in the bucket, which is the time-edge of the bucket furthest towards the future. Specify the timestamp in the number of seconds from the UNIX epoch.