Splunk Search

Easy Epoch time transformation


I have a lot of DB Connect inputs connecting to MS SQL databases. a lot of the data i am pulling from these inputs have multiple date/time fields. Ususally one of the fields is my output timestamp and that will get read correctly. The other date/time fields will end up being converted by splunk to Epoch time. would i need a stanza in props.conf to address this and if so would i need to identify the fields in the stanza?

Tags (3)
0 Karma


If you want the other timestamp fields left alone, you can probably achieve that in SQL. You can cast the column from a TIMESTAMP type to a VARCHAR type. I would be careful, though, of timezone issues with doing this.

Alternately, you could use calculated fields to reproduce human readable times.

0 Karma


any tutorial for doing this one?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...