Hi,
I have a KVstore with time fields. below the definition
root@splunk652_01:/opt/splunk/etc/apps/search/local# cat collections.conf
[lvss_sla_queue_coll]
field.def_id = number
field.earliest_time = time
field.latest_time = time
field.schedule_time = time
field.sla_id = string
replicate = true
When I look at the KV store in the lookup editor (3.10 splunk 6.5.2) this is how it shows up
If I export or use |inputlookup all looks fine
is there something wrong with my data or a lookup editor bug?
Regards,
ILYA
Yeah I'm having the same issue. The author is converting the stored epoch time using milliseconds instead of seconds
I have a fix for this. The fix will be released in version 3.2.1.
Update:
I released version 3.2.1. You will need to clear the browser cache or bump Splunk to see the changes.
Thank you very much Luke
Amazing. Thank you!!!
Submitted an issue https://github.com/LukeMurphey/lookup-editor/issues/39
Thanks for confirming and submitting an issue
Yeah I'm having the same issue. The author is converting the stored epoch time using milliseconds instead of seconds