I have a KVstore with time fields. below the definition
root@splunk652_01:/opt/splunk/etc/apps/search/local# cat collections.conf
field.def_id = number
field.earliest_time = time
field.latest_time = time
field.schedule_time = time
field.sla_id = string
replicate = true
When I look at the KV store in the lookup editor (3.10 splunk 6.5.2) this is how it shows up
If I export or use |inputlookup all looks fine
is there something wrong with my data or a lookup editor bug?
I have a fix for this. The fix will be released in version 3.2.1.
I released version 3.2.1. You will need to clear the browser cache or bump Splunk to see the changes.