We have just completed an upgrade to Splunk Base 7.1.2 and ES 5.1. We have a couple of ongoing investigations in ES and when we look at the details of these investigations in list mode.
We see the correct time and date that the event was logged into ES Investigations. But when we print the document, the time and date change to January 18, 1970
What could cause this issue?
It's a known bug that is fixed in version 5.0.0 of Splunk Enterprise Security. Maybe it was regressed? I'd suggest you follow up with your support contact.