- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/32bfd/32bfde07721e9bdca3366e9f853f892d3d98a74c" alt="bohanlon_splunk bohanlon_splunk"
bohanlon_splunk
data:image/s3,"s3://crabby-images/1f594/1f594b1b4c0941863df1722dd52dd06a5b9a2e11" alt="Splunk Employee Splunk Employee"
Splunk Employee
01-20-2016
01:21 AM
In Enterprise Security, the Threat Intelligence Audit dashboard is not displaying properly.
The _time and run_duration fields are incorrectly displayed when the user is in +GMT.
This is due to the strptime()
conversion in the dashboard's search which looks like this:
eval _time=strptime('row 1', "%Y-%m-%d%T%H:%M:%S-%z")
This will work only for -GMT (-%z), but will not work for any user in +GMT.
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/32bfd/32bfde07721e9bdca3366e9f853f892d3d98a74c" alt="bohanlon_splunk bohanlon_splunk"
bohanlon_splunk
data:image/s3,"s3://crabby-images/1f594/1f594b1b4c0941863df1722dd52dd06a5b9a2e11" alt="Splunk Employee Splunk Employee"
Splunk Employee
01-20-2016
01:24 AM
Answering my own question.
This is seen in ES 3.3.0 and 4.0.1.
Bug logged as SOLNESS-8361.
Workaround is remove the extra -
i.e.
eval _time=strptime('row 1', "%Y-%m-%d%T%H:%M:%S%z")
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/32bfd/32bfde07721e9bdca3366e9f853f892d3d98a74c" alt="bohanlon_splunk bohanlon_splunk"
bohanlon_splunk
data:image/s3,"s3://crabby-images/1f594/1f594b1b4c0941863df1722dd52dd06a5b9a2e11" alt="Splunk Employee Splunk Employee"
Splunk Employee
01-20-2016
01:24 AM
Answering my own question.
This is seen in ES 3.3.0 and 4.0.1.
Bug logged as SOLNESS-8361.
Workaround is remove the extra -
i.e.
eval _time=strptime('row 1', "%Y-%m-%d%T%H:%M:%S%z")
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/150f6/150f6ea44153600540bccf2eab236aa3ee855944" alt="dirkmeeuwsen dirkmeeuwsen"
dirkmeeuwsen
Explorer
01-21-2016
05:27 AM
thanks for adding the solution!
data:image/s3,"s3://crabby-images/1a552/1a552ff33d37f94e7c5bc13132edaa973c529815" alt=""