I use the following eval expression to convert epoch time to human readable format when I search:
... | eval formatted_time=strftime(old_time/1000, "%H:%M:%S %d-%m-%Y")
*old_time = time in epoch format.
Is it possible to do it permanent ?
I mean- To calculation it automatically and not use all the time with the above search ?
Yes, Splunk supports this via a feature called "calculated fields" in props.conf. To do this for a source type called my_custom it would look like this
EVAL-formatted_time=strftime(old_time/1000, "%H:%M:%S %d-%m-%Y")