Splunk Search

how to change time in summary index i want _time not which is having in data i have used eval _time (now ) but it is not working its same showing event date not _ time

abhishekdubey00
Engager

Now
6/1/19
12:31:03.763 AM
2019-06-01 00:31:03.763,

wanted
6/1/19
12:31:03.763 AM
2019-06-01 00:31:03.763

Tags (2)
0 Karma

abhishekdubey00
Engager

wanted
6/6/19
8:17:50.000 AM

2019-06-01 00:31:03.763

now
6/1/19
12:31:03.763 AM
2019-06-01 00:31:03.763

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...