<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Regarding Timestamps in CSV vs PDF in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Regarding-Timestamps-in-CSV-vs-PDF/m-p/115676#M24186</link>
    <description>&lt;P&gt;I have some users who schedule a report to come as a CSV attachment.  Within that the timestamp will display differently from a PDF export of the same data.  Here is an example of the first 4 timestamps of the report as a CSV vs a PDF.&lt;/P&gt;

&lt;P&gt;CSV (_time):&lt;BR /&gt;
1402492281&lt;BR /&gt;
1402464600&lt;BR /&gt;
1402474609&lt;BR /&gt;
1402474608&lt;/P&gt;

&lt;P&gt;PDF (_time):&lt;BR /&gt;
2014-06-11T08:11:21.000-05:00&lt;BR /&gt;
2014-06-11T03:16:49.000-05:00&lt;BR /&gt;
2014-06-11T03:16:48.000-05:00&lt;BR /&gt;
2014-06-11T00:30:00.000-05:00&lt;/P&gt;

&lt;P&gt;I get that the timestamp in the CSV is in unix epoch.  Is there a document that confirms that an export to PDF automatically converts epoch to a more human readable format?&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jun 2014 15:53:12 GMT</pubDate>
    <dc:creator>LiquidTension</dc:creator>
    <dc:date>2014-06-23T15:53:12Z</dc:date>
    <item>
      <title>Regarding Timestamps in CSV vs PDF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Regarding-Timestamps-in-CSV-vs-PDF/m-p/115676#M24186</link>
      <description>&lt;P&gt;I have some users who schedule a report to come as a CSV attachment.  Within that the timestamp will display differently from a PDF export of the same data.  Here is an example of the first 4 timestamps of the report as a CSV vs a PDF.&lt;/P&gt;

&lt;P&gt;CSV (_time):&lt;BR /&gt;
1402492281&lt;BR /&gt;
1402464600&lt;BR /&gt;
1402474609&lt;BR /&gt;
1402474608&lt;/P&gt;

&lt;P&gt;PDF (_time):&lt;BR /&gt;
2014-06-11T08:11:21.000-05:00&lt;BR /&gt;
2014-06-11T03:16:49.000-05:00&lt;BR /&gt;
2014-06-11T03:16:48.000-05:00&lt;BR /&gt;
2014-06-11T00:30:00.000-05:00&lt;/P&gt;

&lt;P&gt;I get that the timestamp in the CSV is in unix epoch.  Is there a document that confirms that an export to PDF automatically converts epoch to a more human readable format?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2014 15:53:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Regarding-Timestamps-in-CSV-vs-PDF/m-p/115676#M24186</guid>
      <dc:creator>LiquidTension</dc:creator>
      <dc:date>2014-06-23T15:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding Timestamps in CSV vs PDF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Regarding-Timestamps-in-CSV-vs-PDF/m-p/115677#M24187</link>
      <description>&lt;P&gt;Adding "convert ctime(_time) as timestamp" to the query allowed the csv export to display a friendlier timestamp.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jul 2014 16:10:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Regarding-Timestamps-in-CSV-vs-PDF/m-p/115677#M24187</guid>
      <dc:creator>LiquidTension</dc:creator>
      <dc:date>2014-07-08T16:10:56Z</dc:date>
    </item>
  </channel>
</rss>

