All Apps and Add-ons

Why is lookup editor not showing correct epoch time from KV Store?

_joe
Contributor

The lookup editor appears to be incorrectly converting epoch time.

For example, I am working on the ES Malware_Tracker and when I pull that KV store up in the event editor, all epoch times are being converted incorrectly (1970/01/19...). If I use inputlookup and convert the corresponding fields to string, I get expected time ranges.

The problem seems identical to answers '730398', "kv-store-time-fields-in-lookup-editor-are-not-show", which was related to bug 4593568 :
https://answers.splunk.com/answers/730398/kv-store-time-fields-in-lookup-editor-are-not-show.html

The problem is, I have a newer 8.0.1 fresh install with the newest version of the lookup editor (3.3.3)

Tags (1)

harish_ka
Communicator

Change field type from 'time' to 'string' in collections.conf

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...