I have the following problem and am wondering if this is a bug or am I doing something wrong:
I use a scheduled search to find some events with a specific windows error ID. Then I look at it as a table using:
No I created a scheduled search based on that, where I send the result as an email with a csv-attachment.
In the csv-attachment (as opposed to the interactive version) I get the _time column filled in epoch (seconds since 1970) format instead of a human readable form that I get in the search app. Is this a bug or do I have to do something to make this work properly. Everything on 5.0.3.
I seems like that _time is converted to the epoch format. But if you want to show it in the conventional format. Please use the strftime() fuction before you do the table
eval TimeStamp=strftime(_time,"%d/%m/%y %H:%M:%s %p")|table TimeStamp,
In the search app you get a humanly readable conversion for time by automagic, underneath it's epoch seconds there as well. You can verify this by adding
| eval foo = _time to some query, it will show epoch seconds for
fóo and humanly readable for `time`.
Manually, this for-view formatting without changing the underlying value is invoked by the SPL command
fieldformat, see more explanation there.