Getting Data In

Convert Epoch time to human date at index time?

mansamusa27
Loves-to-Learn Everything

Hi,

 

I want to convert Epoch time appearing in my events in a field but I want to convert it at index time so that when I search for events instead of 

 

{"@timestamp":1663854197000,"event":{"id":"101........................

 

I want to change it to

{"@timestamp":human readable format,"event":{"id":"101........................

I know that splunk reads the epoch time and converts it to human readable format under the _time field but I want to transform the raw events to have human readable format.

I am assuming I would need to do it on props.conf to do it at index time, maybe SEDCMD could do it I am not sure I just cant get down the right syntax for this I would really appreciate if anyone can help with this.

Thank you in advance!

Labels (5)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...