_time is actually in epoch format, Splunk just converts the format automatically before showing it to you so that it's human readable. So, to add 4 seconds, just do
Note that this is purely a search-time operation - if you want to do this at index-time the problem is much more complex because functions for performing arithmetic etc are not available.
shouldn't the expected outcome be 23:03:39.846 ?
strftime/strptime, %3N, %6N are the variables for milli- and microseconds, respectively.
input time: 23:03:43.936
after subtracting 4.09
expected output time: 23:03:39.022
but output time is 23:03:39
i gave %ms after %S but not working and when i export it to CSV time column is not proper it show ### in the column
got it ..but i am not able to see milliseconds
index=tmidx host="server" index=tmidx host="server" "finished executing normally" | rex field=raw "(?i)Process\s(\"|\"})(?
this is my search