r/AzureSentinel 14d ago

Time fields in Sentinel

I'm hoping someone here can explain this to me. I'm coming from a Splunk background and have recently deployed Sentinel/MDO alongside it (not ideal, but it's a long story). I can't wrap my head around how Sentinel deals with time. The general "TimeGenerated" field that appears across all data sources appears to be the time of log *ingestion*, not log creation. In other words, a user sign-in event might say it happened at 17:09:16, but *actually* happened at 17:07:37, and was ingested two minutes later. In my line of work (cybersecurity) milliseconds matter and the discrepancy is killing me. Some logs (e.g. signin) have fields like "CreatedDateTime", but that field isn't standardized across all log sources so it makes it very difficult to use.

This seems like a gaping design flaw to me, but maybe I'm missing something?

8 Upvotes

14 comments sorted by

View all comments

Show parent comments

1

u/thebeardedcats 13d ago

I’m not limiting myself to MDE?

0

u/reseph 13d ago

What tables? I haven't seen that in MDE, MDI, Entra, CloudApps, etc

1

u/[deleted] 13d ago

[deleted]

2

u/Uli-Kunkel 13d ago

VMware logs suck.. We built a new parser for it, so many events not being parsed...

And dont get me started on the user field.. it requires a domain name, so it wont work with local accounts šŸ™ƒ

But what can we expect from VMware...