Typically, you’d convert from the timestamp (ie epoch time) to something human-readable in your search
Like this:
index=ndx sourcetype=srctp earliest=-4h
| stats max(_time) as rtime min(_time) as etime by fieldA
| sort 0 - rtime + fieldA
| eval rtime=strftime(rtime,"%c"), etime=strftime(etime,"%c")
| rename rtime as "Most Recent" etime as "Earliest"
Splunk strftime docs: https://docs.splunk.com/Documentation/Splunk/8.0.6/SearchReference/DateandTimeFunctions#strftime.28X.2CY.29
Further formatting info for strptime and strftime: https://strftime.org
from User warren – Stack Overflow https://stackoverflow.com/questions/64269848/epoch-time-conversion-to-time-in-splunk/64282363#64282363
via IFTTT