Based on the epoch time value you provided, I am assuming it is with nano seconds. If it is _time, you can add TIME_FORMAT = %s%9N in your props.conf for telling Splunk that timestamp is in epoch form with nanoseconds. If it is not _time, You can create a calculated field using something like this strftime(timefield/pow(10,9),"%Y-%m-%dT%H:%M:%S.%Q") If you are doing it in search: | eval timefield=strftime(tiemfield/pow(10,9),"%Y-%m-%dT%H:%M:%S.%Q")
... View more