Getting Data In

Convert Epoch time to human date at index time?

mansamusa27
Loves-to-Learn Everything

Hi,

 

I want to convert Epoch time appearing in my events in a field but I want to convert it at index time so that when I search for events instead of 

 

{"@timestamp":1663854197000,"event":{"id":"101........................

 

I want to change it to

{"@timestamp":human readable format,"event":{"id":"101........................

I know that splunk reads the epoch time and converts it to human readable format under the _time field but I want to transform the raw events to have human readable format.

I am assuming I would need to do it on props.conf to do it at index time, maybe SEDCMD could do it I am not sure I just cant get down the right syntax for this I would really appreciate if anyone can help with this.

Thank you in advance!

Labels (5)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...