Hello, I am new for Splunk ES.
To configure the ES Incident Review, I use the default setting for the Time which should match the event time format?
event time format
However, my Incident review time shows different format? Where should I change it?
I had the same problem and I managed to find a workaround by creating a new calculated filed for stash sourcetype with the time format I want. (strftime(_time,"%d/%m/%Y %H:%M:%S"))
Then you can add NewTime filed to Incident Review dashboard.
I would also like to know how to modify this to reflect a real timestamp. "Today", "yesterday" are not useful.
Thanks,
Kris