# Sql\_last\_value is literal in query in stead of bind variable

**URL:** <https://discuss.elastic.co/t/sql-last-value-is-literal-in-query-in-stead-of-bind-variable/65489>\
**Category:** Logstash\
**Created:** [November 9, 2016, 1:14pm UTC](https://discuss.elastic.co/t/sql-last-value-is-literal-in-query-in-stead-of-bind-variable/65489 "2016-11-09T13:14:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nlmpij](https://avatars.discourse-cdn.com/v4/letter/n/59ef9b/32.png) [@nlmpij](https://discuss.elastic.co/u/nlmpij)\
**Post date:** [November 9, 2016, 1:14pm UTC](https://discuss.elastic.co/t/sql-last-value-is-literal-in-query-in-stead-of-bind-variable/65489/1 "2016-11-09T13:14:41Z")

</div>

IN my configuration file I'm using jdbc as input

statement =\> "select x.\* from table x where x.snapshot \> :sql\_last\_value"  
last\_run\_metadata\_path =\> "d:/tools/elastic/logstash\_x.lastrun"  
use\_column\_value =\> true  
tracking\_column =\> "snapshot"  
record\_last\_run =\> true

I assumed :sql\_last\_value was used as a bind variable/parameter and not literally replaced by the last value.  
Is there a setting to change behaviour and use as a real bind parameter?

This will prevent pollution of db memory with lots of simular statements with only a different id.

---

<div class="post-metadata">

**Author:** ![nlmpij](https://avatars.discourse-cdn.com/v4/letter/n/59ef9b/32.png) [@nlmpij](https://discuss.elastic.co/u/nlmpij)\
**Post date:** [November 11, 2016, 1:09pm UTC](https://discuss.elastic.co/t/sql-last-value-is-literal-in-query-in-stead-of-bind-variable/65489/2 "2016-11-11T13:09:55Z")

</div>

No way to make a statement a "PreparedStatement" where bind variable will be set with the value of sql\_last\_value?

something like:

parameters =\> { "last\_value" =\> "sql\_last\_value" }  
statement =\> "select x.\* from table x where [x.id](http://x.id) \> :last\_value"

???

Bind variable info:

> **[Using SQL bind variables for application performance and security](https://www.ibm.com/developerworks/library/se-bindvariables/)**
>
> Compare the performance benefits of using bind variables, substitution variables, and literals in your SQL statements, then learn how using bind variables can protect your web application against an SQL injection attack.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 9, 2016, 1:10pm UTC](https://discuss.elastic.co/t/sql-last-value-is-literal-in-query-in-stead-of-bind-variable/65489/3 "2016-12-09T13:10:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
