Splunk Search

continuously DB query with overcome short date format

OBsecurity
Explorer

Hello,
im trying querying HIVE table via 'rising' mode.
query must contain certain timestamp_1 column (otherwise no results are back - massive data)
and must be rising method since results must be real-time.
Unfortunately timestamp column represented with yyyy-MM-dd format only (e.g 2018-01-04) - therefore cannot query real-time.
Table also include bigint date column, i was trying:
1. casting it to readable timestamp - no good.
2. using bigint column as 'rising' - no good.
all of this because timestamp_1 wasnt part of where clause.

  • im using splunk dbx.

any ideas? work arounds?

thanks!

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...