Timestamp Definitions

Supported in:

This document explains common timestamps for events and detections. For more information about timestamps, see Date function .

The following timestamps are related to events:

  • Event timestamp: Time when an event occurred and is stored in the metadata.event_timestamp UDM field. Rules and UDM searches use the metadata.event_timestamp field for queries.
  • Collected timestamp: Time when an event was collected by the local collection infrastructure, such as the forwarder. This is stored in the metadata.collected_timestamp UDM field.
  • Ingested timestamp: Time when an event was ingested by Google Security Operations. This is stored in the metadata.ingested_timestamp UDM field.

The following timestamps are stored with detections:

  • Detection window: For rules with a match section , a detection is created over the time range, called the detection window . The event timestamps for events that triggered the detection are within the detection window.
  • Detection timestamp: For rules with a match section, the detection timestamp is the end time of the detection window. Otherwise, the detection timestamp is the metadata.event_timestamp of the event that generated the detection.
  • Detection created timestamp: Date and time the detection was created by detection engine.

Where timestamps appear in the application

The following sections define where you can view these timestamps in the UI.

UDM Event viewer

To open the UDM Eventview, do the following:

  1. Perform a UDM Search.
  2. In the Eventstab, select an event to open the Event viewer
  3. The UDM eventpane displays the following data:

    • Event timestamp is stored in the metadata.event_timestamp UDM field (1).
    • Ingested timestamp is stored in the metadata.ingested_timestamp UDM field (2).

    UDM Event view

Detections panel

To open the Detectionsview, do the following:

  1. Open Detections> Rules & Detections, and then click the Dashboardbutton.
  2. Click the rule name link under the Rule namecolumn. The Detectionspanel appears and displays the following:

    • Detection timestamp appears in rows that identify a detection (1).
    • Event timestamp appears in rows that identify events (2).

    Detections view

Alert view

To open the Alertview, do the following:

  1. Open Detections> Alerts & IOCs.
  2. Under the Alertstab, click the alert name link in the Namecolumn.
  3. Click the Overviewtab to display the following:

    • Alert (or Detection) created timestamp appears in the Alert Detailspane > Createdfield (1).
    • Detection window appears in the Detection Summarypane > Detection windowfield (2).
    • Detection timestamp appears is in the Detection Summarypane > Alerts detected atfield (3).

    Alert view

Need more help? Get answers from Community members and Google SecOps professionals.

Design a Mobile Site
View Site in Mobile | Classic
Share by: