All Apps and Add-ons

convert First discovered date to human readable date format

leonaheidern
New Member

Hi all I am using the default saved search in tenable app for splunk and the first discovered date is in 1568779472 .

How do I convert this value into a human readable date such as 2019/SEP/18

Tags (1)
0 Karma

leonaheidern
New Member

I am using Tenable.sc . Thanks at least now I know what the source time format is in so I can try updating the search

I am having an issue converting the date time format as the first_found and last_found dates are in the drilldown part of the query

I have tried editing the Source XML with
| eval first_found= strfptime(first_found ,"%25Y-%25m-%25dT%25H:%25M:%25S") | eval last_found= strfptime(last_found ,"%25Y-%25m-%25dT%25H:%25M:%25S")

However when I do this the dashboard becomes unclickable.

0 Karma

nkeuning
Communicator

There are a couple different ways you could do this.
- You could update your splunk search to convert these in real-time.
- You could customize the saved search to convert the timestamp from epoch to string prior to storing it in the lookup table. NOTE: T.sc and T.io provide different timestamp formats or the same values, so if you are using both you will need to take that into consideration with this option.

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.