Finally, the key piece of information! You are expecting this to be an Excel date value. | makeresults
| eval date=45123
| eval _time=(date-25567-2)*24*60*60 Excel uses dates based on the start of ...
See more...
Finally, the key piece of information! You are expecting this to be an Excel date value. | makeresults
| eval date=45123
| eval _time=(date-25567-2)*24*60*60 Excel uses dates based on the start of the 20th Century 1900-01-01, counting in days, whereas, Splunk uses unix-style times based on seconds since 1970-01-01, so, you need to subtract the number of days between these two baseline points, and multiply by the number of seconds in a day. Note that Excel may not be calculating the date correctly since it indexes the first day as 1 (instead of 0) and incorrectly assumes that 1900 was a leap year (which it wasn't), hence the extra -2 days in the calculation. Having said that, you will have to decide whether the _time value returned is correct based on the source of your data i.e. it could be a couple of days out.