Differences on time, event.time and event.time.str meta keys in RSA Security Analytics and NeWitness log sessions.
Issue
What are the differences in time, event.time and event.time.str meta keys found in log sessions in Security Analytics or NetWitness?
Resolution
time: Displays the time at which the event was received by the Log Decoder.event.time: Displays the time when the event was created as found in the event.
event.time.str: Displays the time prefixed by the Log Collector when the event was ingested into it.
Product Details
RSA Product Set: NetWitness Logs & NetworkRSA Product/Service Type: Core Appliance
RSA Version/Condition: 10.x, 11.x
Platform: CentOS
O/S Version: 6, 7
Approval Reviewer Queue
RSA NetWitness Suite Approval Queue