Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why is Splunk DB Connect 2 not capturing the correct timestamp from our Sybase database and the DBmon Tail stops?

$
0
0
Any idea on how to fix the incorrect time stamp being changed or how to use Splunk to condition the timestamp? For some reason between midnight and 1am, Splunk changes the original data from a Sybase database (SQL 2012 Anywhere) ![alt text][1] Top Splunk below: ![alt text][2] Please note that the data has been pulled from 2 different times so the dates will be off. What I am talking about is minutes is not shown in 00:45:00 but in 00:0-15:00 and causes the DB tail to stop. I am trying to use the strptime to change the time format, but am not having any luck. Though, I don’t know if I am doing it right so I don’t think it’s the function that doesn’t work, it very well could be the user. Any help or recommendation would be greatly appreciated. Thanks, Michael [1]: /storage/temp/126254-original-sybase.png [2]: /storage/temp/126255-splunk-translation.png

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>