<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Difference between: Start Time | Generate Time | Receive Time | Elapsed Time in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75380#M41958</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have question for you.&lt;/P&gt;
&lt;P&gt;We have analyzed our log and seems there is something that is not properly correlated.&lt;/P&gt;
&lt;P&gt;Here below a little explanation regarding parameters mentioned:&lt;/P&gt;
&lt;P&gt;------------------------------------------&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Receive Time&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Time the log was received at the management plane&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Generate Time&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Time the log was generated on the dataplane&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Time Logged&lt;/SPAN&gt;&lt;BR /&gt;N/A; Can someone explain this specific parameter?&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Start Time&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Time of session start&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Elapsed Time (sec)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Elapsed time of the session&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Assuming this, I need to understand better this output:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Time_Stamp_Logs" style="width: 565px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3253iC7BF0BFDFCEAB2B8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Time_Stamp_Logs.JPG" alt="Time_Stamp_Logs.JPG" /&gt;&lt;/span&gt;﻿&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I have flagged "Log at session end".&lt;/P&gt;
&lt;P&gt;I suppose that : &lt;SPAN&gt;Generate Time = Start Time + Elapsed Time&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;So we can clearly see from output provided that Elapsed time + Start Time IS NOT equal to Receive Time for line where value is 240.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While for line with value 61, Elapsed Time + Start Time IS EQUAL to Receive Time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any kind of suggestion? Thoughts?&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;Luca&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Mar 2016 15:15:22 GMT</pubDate>
    <dc:creator>TheRealDiz</dc:creator>
    <dc:date>2016-03-29T15:15:22Z</dc:date>
    <item>
      <title>Difference between: Start Time | Generate Time | Receive Time | Elapsed Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75380#M41958</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have question for you.&lt;/P&gt;
&lt;P&gt;We have analyzed our log and seems there is something that is not properly correlated.&lt;/P&gt;
&lt;P&gt;Here below a little explanation regarding parameters mentioned:&lt;/P&gt;
&lt;P&gt;------------------------------------------&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Receive Time&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Time the log was received at the management plane&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Generate Time&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Time the log was generated on the dataplane&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Time Logged&lt;/SPAN&gt;&lt;BR /&gt;N/A; Can someone explain this specific parameter?&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Start Time&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Time of session start&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Elapsed Time (sec)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Elapsed time of the session&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Assuming this, I need to understand better this output:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Time_Stamp_Logs" style="width: 565px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/3253iC7BF0BFDFCEAB2B8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Time_Stamp_Logs.JPG" alt="Time_Stamp_Logs.JPG" /&gt;&lt;/span&gt;﻿&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I have flagged "Log at session end".&lt;/P&gt;
&lt;P&gt;I suppose that : &lt;SPAN&gt;Generate Time = Start Time + Elapsed Time&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;So we can clearly see from output provided that Elapsed time + Start Time IS NOT equal to Receive Time for line where value is 240.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While for line with value 61, Elapsed Time + Start Time IS EQUAL to Receive Time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any kind of suggestion? Thoughts?&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;Luca&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2016 15:15:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75380#M41958</guid>
      <dc:creator>TheRealDiz</dc:creator>
      <dc:date>2016-03-29T15:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between: Start Time | Generate Time | Receive Time | Elapsed Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75384#M41959</link>
      <description>&lt;P&gt;Are you looking at the same session ID?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2016 16:08:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75384#M41959</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-03-29T16:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between: Start Time | Generate Time | Receive Time | Elapsed Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75386#M41960</link>
      <description>&lt;P&gt;Yeap!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2016 16:11:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75386#M41960</guid>
      <dc:creator>TheRealDiz</dc:creator>
      <dc:date>2016-03-29T16:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between: Start Time | Generate Time | Receive Time | Elapsed Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75389#M41961</link>
      <description>&lt;P&gt;So I'm looking at an "end" log with a "tcp-fin" session end reason for an application "web-browsing" and have this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="x-grid3-row "&gt;
&lt;TABLE class="x-grid3-row-table" border="0" cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="x-grid3-col x-grid3-cell x-grid3-td-id2  x-grid-selectable"&gt;
&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Start Time&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD class="x-grid3-col x-grid3-cell x-grid3-td-3  x-grid-selectable"&gt;
&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;2016/03/29 10:26:27&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;DIV class="x-grid3-row "&gt;
&lt;TABLE class="x-grid3-row-table" border="0" cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="x-grid3-col x-grid3-cell x-grid3-td-id2  x-grid-selectable"&gt;
&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Receive Time&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD class="x-grid3-col x-grid3-cell x-grid3-td-3  x-grid-selectable"&gt;
&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;2016/03/29 10:35:29&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;DIV class="x-grid3-row  x-grid3-row-last  x-grid3-row-over"&gt;
&lt;TABLE class="x-grid3-row-table" border="0" cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="x-grid3-col x-grid3-cell x-grid3-td-id2  x-grid-selectable"&gt;
&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Elapsed Time(sec)&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD class="x-grid3-col x-grid3-cell x-grid3-td-3  x-grid-selectable"&gt;
&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;540&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The difference from the Start to receive time is 542 seconds. &amp;nbsp;I'm guessing there's a delta of 2 seconds because of processing time?&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 29 Mar 2016 16:22:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75389#M41961</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-03-29T16:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between: Start Time | Generate Time | Receive Time | Elapsed Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75440#M41977</link>
      <description>&lt;P&gt;The receive time is when the log is 'received' by the management plane to be written in the log database.&lt;/P&gt;
&lt;P&gt;Depending on the management plane load, dataplane load, log rate, log volume and several other factors, the receive time can be one or several seconds after it was created and is not necessarily correlated in any way to the actual session, it's just an indication when the log itself was written to file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This can become more apparent in an environment where panorama is located far away from a managed firewall where there is a potential break in communication and the firewall is not able to send logs real-time&lt;/P&gt;
&lt;P&gt;The receive time may then be minutes or even hours, depending on the gap in communication, from the start and elapsed time&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 09:28:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75440#M41977</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-03-30T09:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between: Start Time | Generate Time | Receive Time | Elapsed Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75445#M41978</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot for your explanation.&lt;/P&gt;
&lt;P&gt;I agree with you but I need to find a point on this one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In conclusion if Generate Time is not strictly related to Start + Elapsed Time, in order to be accurate on Session Time:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Elapsed Time = Is duration of session from SYN to FIN&lt;/P&gt;
&lt;P&gt;Session Ended = Start Time + Elapsed (I suppose)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example&lt;/P&gt;
&lt;P&gt;Start Time = 10:00:00&lt;/P&gt;
&lt;P&gt;Elapsed Time= 60 sec&lt;/P&gt;
&lt;P&gt;Generate Time = 10:06:00 (Depends on data-plane and management-plane load and other several factors)&lt;/P&gt;
&lt;P&gt;Session Ended = 10:00:00 + 60 sec = 10:01:00&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need to be accurate when Session is ended.&lt;/P&gt;
&lt;P&gt;Correct me if I am wrong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also last question is:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-----------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Time Logged&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;N/A; Can someone explain this specific parameter?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-----------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks and Best Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Luca&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 10:52:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75445#M41978</guid>
      <dc:creator>TheRealDiz</dc:creator>
      <dc:date>2016-03-30T10:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between: Start Time | Generate Time | Receive Time | Elapsed Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75456#M41980</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there's even a difference between receive time and generate time&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Receive time is when the management plane receives the log entry andsends it to the database&lt;/P&gt;
&lt;P&gt;Generate time is when the log is 'created' on the dataplane which depends on session-start (start time + time needed for dataplane to create the log) or session-end (start time + time elapsed + time needed for dataplane to create the log)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so for your example:&lt;/P&gt;
&lt;P&gt;Start Time = 10:00:00&lt;/P&gt;
&lt;P&gt;Elapsed Time= 60 sec&lt;/P&gt;
&lt;P&gt;Generate Time - session start = 10:00:00 (Depends on &lt;STRONG&gt;data-plane&lt;/STRONG&gt; load)&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Receive&amp;nbsp;Time - session start = 10:00:00 (Depends on &lt;STRONG&gt;management-plane&lt;/STRONG&gt; load and other factors)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Generate Time - session end = 10:01:00 (Depends on &lt;STRONG&gt;data-plane&lt;/STRONG&gt; load)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Receive&amp;nbsp;Time - session end = 10:01:00 (Depends on &lt;STRONG&gt;management-plane&lt;/STRONG&gt; load and other factors)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Session Ended = 10:00:00 + 60 sec = 10:01:00&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;a session is marked as 'ended' when either both sides send a FIN, RST or the session is marked as closed for other reasons OR, in case of a timeout, the timeout expires and the session is marked as closed by (idle) timeout&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;time logged should be when the log is actually written to the database&amp;nbsp;(as log files may be put in a write queue for the database)&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 12:14:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75456#M41980</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-03-30T12:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between: Start Time | Generate Time | Receive Time | Elapsed Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75458#M41982</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Perfect!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In conclusion there is not a field that can indicate exactly when a Session is ended the only way is to calculate it with:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--------------------------------------------------&lt;/P&gt;
&lt;P&gt;Session Ended = Start Time + Elapsed Time&lt;/P&gt;
&lt;P&gt;---------------------------------------------------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's important and main information on my side, simply because I need to know exactly when a session is ended.&lt;/P&gt;
&lt;P&gt;Also thanks to&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz﻿&lt;/a&gt;&amp;nbsp;for your response!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR&lt;/P&gt;
&lt;P&gt;Luca&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 12:40:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-start-time-generate-time-receive-time-elapsed/m-p/75458#M41982</guid>
      <dc:creator>TheRealDiz</dc:creator>
      <dc:date>2016-03-30T12:40:57Z</dc:date>
    </item>
  </channel>
</rss>

