Splunk Enterprise Security

How to change the event time of ES Incident Review

hwang2021
Loves-to-Learn Lots

Hello, I am new for Splunk ES.

To configure the ES Incident Review, I use the default setting for the Time which should match the event time format?

hwang2021_0-1627578638240.png

event time formathwang2021_2-1627578897536.png

However, my Incident review time shows different format? Where should I change it?

hwang2021_3-1627579128956.png

 

 

Labels (2)
0 Karma

krispyswitch
Loves-to-Learn

I would also like to know how to modify this to reflect a real timestamp.  "Today", "yesterday" are not useful.

Thanks,

Kris

 

0 Karma