Hi,
I want to convert Epoch time appearing in my events in a field but I want to convert it at index time so that when I search for events instead of
{"@timestamp":1663854197000,"event":{"id":"101........................
I want to change it to
{"@timestamp":human readable format,"event":{"id":"101........................
I know that splunk reads the epoch time and converts it to human readable format under the _time field but I want to transform the raw events to have human readable format.
I am assuming I would need to do it on props.conf to do it at index time, maybe SEDCMD could do it I am not sure I just cant get down the right syntax for this I would really appreciate if anyone can help with this.
Thank you in advance!