Dashboards & Visualizations

How to convert _time to a human readable format and display Time and Date in a single value panel?

jclehmuth
Path Finder

This sounds easy but I can't seem to figure it out. I'm creating an "Admin" dashboard and a couple of the panels are time last "x" tool ran. The most recent event received from host "x" is what I need to retrieve a time stamp from and post it in a panel.

Currently I have this
host ="10.0.33.210" | chart first(_time)

which outputs : 1418565983

How do I convert that into readable time and date?
I'm attempting to just use a single value panel.

Thanks in advance.

Tags (2)
1 Solution

somesoni2
Revered Legend

Try this

host ="10.0.33.210" | chart first(_time) as Time | convert ctime(Time)

Other options

host ="10.0.33.210" | chart first(_time) as Time | eval Time=strftime(Time,"%Y/%m/%d %H:%M:%S")

host ="10.0.33.210" | chart first(_time) as Time | eval Time=strftime(Time,"%+")

View solution in original post

somesoni2
Revered Legend

Try this

host ="10.0.33.210" | chart first(_time) as Time | convert ctime(Time)

Other options

host ="10.0.33.210" | chart first(_time) as Time | eval Time=strftime(Time,"%Y/%m/%d %H:%M:%S")

host ="10.0.33.210" | chart first(_time) as Time | eval Time=strftime(Time,"%+")

jclehmuth
Path Finder

That worked thanks. I can't believe I couldn't figure that out.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...