Splunk Enterprise Security

Is it possible to change time format for column Receipt Time in Incident Review window?

leszek109
Engager

Is it possible to change format time for the column "Receipt Time" in "Incident Review"?

Currently I see this time in format like this: 3/10/21 4:00:47.000 PM

I would like to change displaying it to 24h format.

I don't want change the format _time from logs, only _time from "Incident Review" which shows time of notable event.

Thank you for the help.

Labels (2)
0 Karma
1 Solution

aakwah
Builder
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...