Getting Data In

Why is time displayed always in 12 hour format in the events tab of Splunk?

Explorer

Hello,

I have a proper extraction of my timestamp and when I print my _time, I can see the time in 24 hour format. But, when I visually see the data in the events tab, the time associated to my event is in 12-hour format.

eg: The time of my event 1 is 13:46.

When I give "table _time", I see 13:46 but when I see the event 1 under events tab, I see 1:46 PM. Is there a way to change the time format on how we look at it in the events tab?

Tags (2)
0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!