All Apps and Add-ons

KV Store Time fields in lookup editor are not showing up correctly

Path Finder

Hi,
I have a KVstore with time fields. below the definition
root@splunk652_01:/opt/splunk/etc/apps/search/local# cat collections.conf
[lvss_sla_queue_coll]
field.def_id = number
field.earliest_time = time
field.latest_time = time
field.schedule_time = time
field.sla_id = string
replicate = true

When I look at the KV store in the lookup editor (3.10 splunk 6.5.2) this is how it shows up
alt text

If I export or use |inputlookup all looks fine
alt text

is there something wrong with my data or a lookup editor bug?

Regards,
ILYA

0 Karma
1 Solution

Explorer

Yeah I'm having the same issue. The author is converting the stored epoch time using milliseconds instead of seconds

View solution in original post

0 Karma

Champion

I have a fix for this. The fix will be released in version 3.2.1.

Update:
I released version 3.2.1. You will need to clear the browser cache or bump Splunk to see the changes.

0 Karma

Path Finder

Thank you very much Luke

0 Karma

Explorer

Amazing. Thank you!!!

0 Karma

Explorer
0 Karma

Path Finder

Thanks for confirming and submitting an issue

0 Karma

Explorer

Yeah I'm having the same issue. The author is converting the stored epoch time using milliseconds instead of seconds

View solution in original post

0 Karma