Splunk Enterprise Security

How to change the event time of ES Incident Review

hwang2021
Loves-to-Learn Lots

Hello, I am new for Splunk ES.

To configure the ES Incident Review, I use the default setting for the Time which should match the event time format?

hwang2021_0-1627578638240.png

event time formathwang2021_2-1627578897536.png

However, my Incident review time shows different format? Where should I change it?

hwang2021_3-1627579128956.png

 

 

Labels (2)
0 Karma

aakwah
Builder

I had the same problem and I managed to find a workaround by creating a new calculated filed for stash sourcetype with the time format I want. (strftime(_time,"%d/%m/%Y %H:%M:%S"))

 

Then you can add NewTime filed to Incident Review dashboard.

aakwah_0-1663334547986.png

 

Tags (1)

krispyswitch
Loves-to-Learn

I would also like to know how to modify this to reflect a real timestamp.  "Today", "yesterday" are not useful.

Thanks,

Kris

 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 1 release of new security content via the ...

There's No Place Like Chrome and the Splunk Platform

Watch On DemandMalware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

The Great Resilience Quest: 5th Leaderboard Update

The fifth leaderboard update for The Great Resilience Quest is out >> 🏆 Check out the ...