All Apps and Add-ons

Why is lookup editor not showing correct epoch time from KV Store?

_joe
Communicator

The lookup editor appears to be incorrectly converting epoch time.

For example, I am working on the ES Malware_Tracker and when I pull that KV store up in the event editor, all epoch times are being converted incorrectly (1970/01/19...). If I use inputlookup and convert the corresponding fields to string, I get expected time ranges.

The problem seems identical to answers '730398', "kv-store-time-fields-in-lookup-editor-are-not-show", which was related to bug 4593568 :
https://answers.splunk.com/answers/730398/kv-store-time-fields-in-lookup-editor-are-not-show.html

The problem is, I have a newer 8.0.1 fresh install with the newest version of the lookup editor (3.3.3)

Labels (1)
Tags (1)

harish_ka
Communicator

Change field type from 'time' to 'string' in collections.conf

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...