Splunk Enterprise Security

Parsing epoch time: Why is there Enterprise Security ip_intel issue with time value?

licroBI_0x
Observer

Hi all,

I would like some help related to the wrong time value in Threat Intelligence (KV Store Lookup ) "ip_intel".

Each entry has a value of "1970/01/20 02:45:00" or similar to it...the date is same... 

I would assume that this is an issue related to parsing epoch time? But I am having a hard time identifying how this could be fixed. I would be happy with the approximate time of upload to "ip_intel".

If anyone has suggestions I would appreciate it. Thanks

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...