The lookup editor appears to be incorrectly converting epoch time.
For example, I am working on the ES Malware_Tracker and when I pull that KV store up in the event editor, all epoch times are being converted incorrectly (1970/01/19...). If I use inputlookup and convert the corresponding fields to string, I get expected time ranges.
The problem seems identical to answers '730398', "kv-store-time-fields-in-lookup-editor-are-not-show", which was related to bug 4593568 :
https://answers.splunk.com/answers/730398/kv-store-time-fields-in-lookup-editor-are-not-show.html
The problem is, I have a newer 8.0.1 fresh install with the newest version of the lookup editor (3.3.3)
Change field type from 'time' to 'string' in collections.conf