Splunk Enterprise Security

How to change the event time of ES Incident Review

hwang2021
Loves-to-Learn Lots

Hello, I am new for Splunk ES.

To configure the ES Incident Review, I use the default setting for the Time which should match the event time format?

hwang2021_0-1627578638240.png

event time formathwang2021_2-1627578897536.png

However, my Incident review time shows different format? Where should I change it?

hwang2021_3-1627579128956.png

 

 

Labels (2)
0 Karma

aakwah
Builder

I had the same problem and I managed to find a workaround by creating a new calculated filed for stash sourcetype with the time format I want. (strftime(_time,"%d/%m/%Y %H:%M:%S"))

 

Then you can add NewTime filed to Incident Review dashboard.

aakwah_0-1663334547986.png

 

Tags (1)

krispyswitch
Loves-to-Learn

I would also like to know how to modify this to reflect a real timestamp.  "Today", "yesterday" are not useful.

Thanks,

Kris

 

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...