You can set the time to your favourite format
your search |eval _time=strftime(_time,"%d/%m/%Y %H:%M:%S")
You can set it permanent in props.conf if you don't care about millisecond precision in your searches
[<spec>] TIME_FORMAT = %d/%m/%Y %H:%M:%S
Thank you for your answer, but when I write your command, I have :
After personalize, it's same problem...
Thanks you so much ! It's work !
But when I write in /opt/splunk/etc/apps/search/local/props.conf
TIME_FORMAT = %d/%m/%Y %H:%M:%S
It's not work... I restart Splunk, wait +12h and it's not ok...
Sorry you can ignore this part and remove this settings. This is for extracting the timestamp from your event(initially i thought so). Since your timestamp extraction is fine you don't need this.