Same issue. Any updates on this?
2 of 2 people found this helpful
I figured out my issue. You need to make sure that you follow the date Timstamp format for ODBC. Refer to this link from Micorsoft on ODBC Datetime Format.
In my case, I already had a date field that was being tabled. I cloned this and changed the format to:
|eval TS=strftime(_time, "%Y-%m-%d %H:%M:%S")
That did the trick. The field comes into Tableau from Splunk as a date field, not as a string. The order of the YMD matters, as I tried a few other formats.
With this coming into Tableau as a Date Field now, I can do incremental refresh's.
Hope this helps, and will save others countless hours of troubleshooting this issue.
Thanks so much sir, you just saved me a headache and an amazing out of time.
This should be marked the answer, as it appears to address what the underlying issue is as well as the solution.
Thanks for the help, Matt!
I forgot about this one. You are welcome!