There are numerous posts on converting timestamps to milliseconds, and formating the _time field (may involve changes to the sourcetype) so the actual syntax/solution will be based on your data set. Here is a good example of converting to milleseconds https://community.splunk.com/t5/Splunk-Search/TimeFormat-conversion-to-millisecond/m-p/212326 If you are looking to search on the _raw field, adding that to a data model is not advisable. One of its purposes of a data model is to reduce and consolidate the number of fields and size of events to a summary version so adding that field would directly contradict that purpose. I would recommend just using that field for your search or adding additional field extractions to the data and then adding the new fields to the custom DM.
... View more