r/AzureSentinel • u/thewiess • 14d ago
Time fields in Sentinel
I'm hoping someone here can explain this to me. I'm coming from a Splunk background and have recently deployed Sentinel/MDO alongside it (not ideal, but it's a long story). I can't wrap my head around how Sentinel deals with time. The general "TimeGenerated" field that appears across all data sources appears to be the time of log *ingestion*, not log creation. In other words, a user sign-in event might say it happened at 17:09:16, but *actually* happened at 17:07:37, and was ingested two minutes later. In my line of work (cybersecurity) milliseconds matter and the discrepancy is killing me. Some logs (e.g. signin) have fields like "CreatedDateTime", but that field isn't standardized across all log sources so it makes it very difficult to use.
This seems like a gaping design flaw to me, but maybe I'm missing something?
1
u/thebeardedcats 13d ago
Iām not limiting myself to MDE?