https://bugs.openldap.org/show_bug.cgi?id=9745
--- Comment #3 from Quanah Gibson-Mount quanah@openldap.org --- (In reply to Howard Chu from comment #2)
The correct path forward here is to submit an enhancement to Splunk to get it to parse this hex timestamp format.
Splunk already supports this:
https://community.splunk.com/t5/Getting-Data-In/hex-encoded-unix-timestamp/m...