Splunk Enterprise Security

How to change the event time of ES Incident Review

hwang2021
Loves-to-Learn Lots

Hello, I am new for Splunk ES.

To configure the ES Incident Review, I use the default setting for the Time which should match the event time format?

hwang2021_0-1627578638240.png

event time formathwang2021_2-1627578897536.png

However, my Incident review time shows different format? Where should I change it?

hwang2021_3-1627579128956.png

 

 

Labels (2)
0 Karma

aakwah
Builder

I had the same problem and I managed to find a workaround by creating a new calculated filed for stash sourcetype with the time format I want. (strftime(_time,"%d/%m/%Y %H:%M:%S"))

 

Then you can add NewTime filed to Incident Review dashboard.

aakwah_0-1663334547986.png

 

Tags (1)

krispyswitch
Loves-to-Learn

I would also like to know how to modify this to reflect a real timestamp.  "Today", "yesterday" are not useful.

Thanks,

Kris

 

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...