Splunk Enterprise Security

How to change the event time of ES Incident Review

hwang2021
Loves-to-Learn Lots

Hello, I am new for Splunk ES.

To configure the ES Incident Review, I use the default setting for the Time which should match the event time format?

hwang2021_0-1627578638240.png

event time formathwang2021_2-1627578897536.png

However, my Incident review time shows different format? Where should I change it?

hwang2021_3-1627579128956.png

 

 

Labels (2)
0 Karma

aakwah
Builder

I had the same problem and I managed to find a workaround by creating a new calculated filed for stash sourcetype with the time format I want. (strftime(_time,"%d/%m/%Y %H:%M:%S"))

 

Then you can add NewTime filed to Incident Review dashboard.

aakwah_0-1663334547986.png

 

Tags (1)

krispyswitch
Loves-to-Learn

I would also like to know how to modify this to reflect a real timestamp.  "Today", "yesterday" are not useful.

Thanks,

Kris

 

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...