Splunk Search

Why is the rename command not working when using it to rename with _time field?

New Member

Hello Team,

Whenever i use the rename command to rename the _time field than output comes in the binary fomart.

For Eg. :- _time is 2020/07/21 than i rename to Time 1592830387

Labels (2)
Tags (1)
0 Karma

Ultra Champion

_time is unix_epoch_time. It displays human readable.
if _time renames other name, it displays original value.


As @to4kawa said it's unix epoch and you should use strftime (newField, "<time format string>") to see it correctly in human readable format. See more:

r. Ismo

Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...