Please post the URL for the sample data you are referring to. (1) Essentially _time should represent the time included within the raw audit event (when it can be determined): https://docs.splunk.com/Documentation/Splunk/6.4.0/Data/HowSplunkextractstimestamps You can convert _time as "H:MM:SS" format: index=* | eval t=strftime(_time, "%I:%M:%S") | table _time, t You can convert _time as "HH:MM:SS" format: index=* | eval t=strftime(_time, "%H:%M:%S") | table _time, t https://docs.splunk.com/Documentation/Splunk/8.0.6/SearchReference/Commontimeformatvariables Leave off the trailing pipe into table once you have confirmed that is what you wanted.
... View more