I am creating some of my first dashboards, and I am having trouble working out how to change the output in the column titled Time to something humanly readable.
Can somebody please point me to what I need to change in the in the search criteria
Hi @j666gak
Adding this to your search should do the trick
eval Time=strftime(Time, "%m/%d/%Y %H:%M:%S")
Hi @j666gak
Adding this to your search should do the trick
eval Time=strftime(Time, "%m/%d/%Y %H:%M:%S")
Here is some supplemental reading from documentation on various ways to convert field values.
http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Convert
http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/CommonEvalFunctions