Getting Data In

Convert Epoch time to human date at index time?

mansamusa27
Loves-to-Learn Everything

Hi,

 

I want to convert Epoch time appearing in my events in a field but I want to convert it at index time so that when I search for events instead of 

 

{"@timestamp":1663854197000,"event":{"id":"101........................

 

I want to change it to

{"@timestamp":human readable format,"event":{"id":"101........................

I know that splunk reads the epoch time and converts it to human readable format under the _time field but I want to transform the raw events to have human readable format.

I am assuming I would need to do it on props.conf to do it at index time, maybe SEDCMD could do it I am not sure I just cant get down the right syntax for this I would really appreciate if anyone can help with this.

Thank you in advance!

Labels (5)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...