Splunk 6.2.6, DB Connect 2.1.1
When I run a SQL query with a / inside, Splunk will always return 0 rows. For example, when running against an Oracle DB:
SELECT * FROM V$ACTIVE_SESSION_HISTORY
WHERE sample_time >= (SYSDATE-__0.0833__) AND sample_time < (SYSDATE+1)
Returns 700+ rows
SELECT * FROM V$ACTIVE_SESSION_HISTORY
WHERE sample_time >= (SYSDATE-__2/24__) AND sample_time < (SYSDATE+1)
Returns 0 rows
Is there a way to escape the / character in the query?
... View more