Splunk Search

dbinspect fields names and format changed in 6.*

mataharry
Communicator

I was using dbinpect to calculates the first and last events in my buckets.
In splunk 4.* and 5.*, it was returning 2 fields earliestTime and latestTime as a date in my SH timezone.

But I do not find those fields anymore in 6.*, how to get them ?

Tags (2)
1 Solution

yannK
Splunk Employee
Splunk Employee

Yes, the format of dbinspect changed in 6.*
see http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Dbinspect

The time fields were renamed and converted to epoch time.

  • earliestTime (in formatted time ) became endEpoch (in epoch)
  • latestTime (in formatted time ) became startEpoch (in epoch)

You can update your searches to use the new fields, or do a simple conversion.

| dbinspect
| convert ctime(endEpoch) AS earliestTime
| convert ctime(startEpoch) AS latestTime

View solution in original post

dlutzy
Engager

you need to switch:

earliestTime (in formatted time ) became startEpoch (in epoch)
latestTime (in formatted time ) became endEpoch (in epoch)

yannK
Splunk Employee
Splunk Employee

Yes, the format of dbinspect changed in 6.*
see http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Dbinspect

The time fields were renamed and converted to epoch time.

  • earliestTime (in formatted time ) became endEpoch (in epoch)
  • latestTime (in formatted time ) became startEpoch (in epoch)

You can update your searches to use the new fields, or do a simple conversion.

| dbinspect
| convert ctime(endEpoch) AS earliestTime
| convert ctime(startEpoch) AS latestTime

mattymo
Splunk Employee
Splunk Employee
| convert ctime(endEpoch) AS latestTime | convert ctime(startEpoch) AS earliestTime

gotta get yannK to flip the fields in the convert

startEpoch - The timestamp for the first event in the bucket (the time-edge of the bucket furthest towards the past), in number of seconds from the UNIX epoch.

endEpoch - The timestamp for the last event in the bucket, which is the time-edge of the bucket furthest towards the future. Specify the timestamp in the number of seconds from the UNIX epoch.

- MattyMo
0 Karma
Get Updates on the Splunk Community!

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...