<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question About Custom Logs Time Field in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/question-about-custom-logs-time-field/m-p/597052#M7158</link>
    <description>&lt;P&gt;Hi Jmazzeo,&lt;/P&gt;
&lt;P&gt;&amp;gt;Is your "datetime" field rounding to zero the seconds?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;No.&lt;/P&gt;
&lt;P&gt;To show the gap, I build apache server, and&amp;nbsp; generate log with using shell script which generate log each 10 seconds.&lt;/P&gt;
&lt;P&gt;So original datetime field's seconds data will be zero.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Sep 2024 00:19:25 GMT</pubDate>
    <dc:creator>H.Fukuda</dc:creator>
    <dc:date>2024-09-06T00:19:25Z</dc:date>
    <item>
      <title>Question About Custom Logs Time Field</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/question-about-custom-logs-time-field/m-p/596664#M7140</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Question&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I want to replace _time field value with original timestamp, but I can not find way to do this.&amp;nbsp;&lt;BR /&gt;Please tell me how to replace _time field value or&amp;nbsp;Is this not possible due to specifications?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Background&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;When we collect logs from XDR Collector, which ingest three fields which related time.&lt;/P&gt;
&lt;P&gt;First one is _time, which is generated by XDR Collector.&lt;/P&gt;
&lt;P&gt;Second is _insert_time, which is generated by Cortex XDR.&lt;/P&gt;
&lt;P&gt;Last one is original timestamp which recorded in log ( which included _raw_log or single dedicate field using parsing rule or filebeat setting)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example, if I ingest apache http severlog, then it shows like this.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HFukuda_0-1725412582774.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61913iB4C2CC90B638C8DE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="HFukuda_0-1725412582774.png" alt="HFukuda_0-1725412582774.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Between _time and datetime(which was created by parsing rule from _raw_log field), there are some gaps around 1 to 10 seconds.&lt;BR /&gt;I want to erase these gaps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2024 01:20:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/question-about-custom-logs-time-field/m-p/596664#M7140</guid>
      <dc:creator>H.Fukuda</dc:creator>
      <dc:date>2024-09-04T01:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Question About Custom Logs Time Field</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/question-about-custom-logs-time-field/m-p/597017#M7152</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/453436187"&gt;@H.Fukuda&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The _time fields is a system field that takes the value from the data entry's timestamp. If unknown, then the value is the time the data entry was added to the database. In your case you have a timestamp value in the logs, and looks like is accurate.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is your "datetime" field rounding to zero the seconds?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 18:42:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/question-about-custom-logs-time-field/m-p/597017#M7152</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-09-05T18:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Question About Custom Logs Time Field</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/question-about-custom-logs-time-field/m-p/597052#M7158</link>
      <description>&lt;P&gt;Hi Jmazzeo,&lt;/P&gt;
&lt;P&gt;&amp;gt;Is your "datetime" field rounding to zero the seconds?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;No.&lt;/P&gt;
&lt;P&gt;To show the gap, I build apache server, and&amp;nbsp; generate log with using shell script which generate log each 10 seconds.&lt;/P&gt;
&lt;P&gt;So original datetime field's seconds data will be zero.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 00:19:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/question-about-custom-logs-time-field/m-p/597052#M7158</guid>
      <dc:creator>H.Fukuda</dc:creator>
      <dc:date>2024-09-06T00:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Question About Custom Logs Time Field</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/question-about-custom-logs-time-field/m-p/597404#M7173</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="paIoaItonetworks_0-1725970479874.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62165i824DC653E6FB5848/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="paIoaItonetworks_0-1725970479874.png" alt="paIoaItonetworks_0-1725970479874.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Unfortunately, these fields will always be shown&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 12:15:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/question-about-custom-logs-time-field/m-p/597404#M7173</guid>
      <dc:creator>paIoaItonetworks</dc:creator>
      <dc:date>2024-09-10T12:15:28Z</dc:date>
    </item>
  </channel>
</rss>

