Splunk Enterprise Security

How to change the event time of ES Incident Review

Loves-to-Learn Lots

Hello, I am new for Splunk ES.

To configure the ES Incident Review, I use the default setting for the Time which should match the event time format?


event time formathwang2021_2-1627578897536.png

However, my Incident review time shows different format? Where should I change it?




Labels (2)
0 Karma


I had the same problem and I managed to find a workaround by creating a new calculated filed for stash sourcetype with the time format I want. (strftime(_time,"%d/%m/%Y %H:%M:%S"))


Then you can add NewTime filed to Incident Review dashboard.



Tags (1)


I would also like to know how to modify this to reflect a real timestamp.  "Today", "yesterday" are not useful.




0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 1 release of new security content via the ...

There's No Place Like Chrome and the Splunk Platform

Watch On DemandMalware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

The Great Resilience Quest: 5th Leaderboard Update

The fifth leaderboard update for The Great Resilience Quest is out >> 🏆 Check out the ...