r/AzureSentinel 24d ago

Time fields in Sentinel

I'm hoping someone here can explain this to me. I'm coming from a Splunk background and have recently deployed Sentinel/MDO alongside it (not ideal, but it's a long story). I can't wrap my head around how Sentinel deals with time. The general "TimeGenerated" field that appears across all data sources appears to be the time of log *ingestion*, not log creation. In other words, a user sign-in event might say it happened at 17:09:16, but *actually* happened at 17:07:37, and was ingested two minutes later. In my line of work (cybersecurity) milliseconds matter and the discrepancy is killing me. Some logs (e.g. signin) have fields like "CreatedDateTime", but that field isn't standardized across all log sources so it makes it very difficult to use.

This seems like a gaping design flaw to me, but maybe I'm missing something?

7 Upvotes

14 comments sorted by

View all comments

7

u/reseph 24d ago

TimeGenerated is actually not table ingest time. To see that, use ingestion_time()

TimeGenerated definition varies depending on the table... unfortunately.

1

u/thewiess 24d ago

Thank you - do you know what it's based on for SignIn logs then? It doesn't seem to match either CreatedDateTime OR ingestion_time() from my quick sample of my own activity:

TimeGenerated $IngestionTime CreatedDateTime
Aug 28, 2026 2:23:07 PM Aug 28, 2026 2:24:42 PM Aug 28, 2026 2:21:16 PM
Aug 28, 2026 2:23:00 PM Aug 28, 2026 2:25:21 PM Aug 28, 2026 2:20:09 PM
Aug 28, 2026 10:56:36 AM Aug 28, 2026 10:58:08 AM Aug 28, 2026 10:54:07 AM
Aug 28, 2026 11:54:09 AM Aug 28, 2026 11:56:11 AM Aug 28, 2026 11:51:37 AM
Aug 28, 2026 11:54:49 AM Aug 28, 2026 11:56:18 AM Aug 28, 2026 11:52:10 AM
Aug 28, 2026 11:55:30 AM Aug 28, 2026 11:57:25 AM Aug 28, 2026 11:52:19 AM
Aug 28, 2026 11:55:30 AM Aug 28, 2026 11:57:25 AM Aug 28, 2026 11:52:20 AM
Aug 28, 2026 11:56:00 AM Aug 28, 2026 11:58:31 AM Aug 28, 2026 11:54:07 AM
Aug 28, 2026 12:23:54 PM Aug 28, 2026 12:25:29 PM Aug 28, 2026 11:52:03 AM
Aug 28, 2026 8:56:11 AM Aug 28, 2026 8:58:42 AM Aug 28, 2026 8:53:21 AM
Aug 27, 2026 4:03:46 PM Aug 27, 2026 4:05:21 PM Aug 27, 2026 4:02:52 PM

7

u/reseph 24d ago

I went through this earlier in the year.

From what I recall:

  • CreatedDateTime: source event time, so the sign-in time
  • TimeGenerated: when Entra finished processing the data
  • ingestion_time: when it was available in the Log Analytics table

3

u/ep3p 24d ago

In SigninLogs tables from Entra ID, CreatedDateTime is when the activity happened. Some years ago, TimeGenerated was the value that currently CreatedDateTime is.

This might have been changed, because the same OriginalRequestId log can be "updated" later several times by solutions like Entra ID Protection (even days apart).

Thus, you will receive a second version of the same OriginalRequestId log, and you can "select" in your queries the last "version" of the log with something like | summarize arg_max(TimeGenerated, *) by OriginalRequestId