All Apps and Add-ons

Why is lookup editor not showing correct epoch time from KV Store?

_joe
Communicator

The lookup editor appears to be incorrectly converting epoch time.

For example, I am working on the ES Malware_Tracker and when I pull that KV store up in the event editor, all epoch times are being converted incorrectly (1970/01/19...). If I use inputlookup and convert the corresponding fields to string, I get expected time ranges.

The problem seems identical to answers '730398', "kv-store-time-fields-in-lookup-editor-are-not-show", which was related to bug 4593568 :
https://answers.splunk.com/answers/730398/kv-store-time-fields-in-lookup-editor-are-not-show.html

The problem is, I have a newer 8.0.1 fresh install with the newest version of the lookup editor (3.3.3)

Labels (1)
Tags (1)

harish_ka
Communicator

Change field type from 'time' to 'string' in collections.conf

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...