Skip to main content
Panther Knowledge Base

How to resolve "EventTime: DecodeTime" parsing error when testing schemas with pantherlog

Issue

When testing a schema with pantherlog, you get an error of the following form:

EventTime: DecodeTime: parsing time "..." as "...": cannot parse "..." as "...", error found in #10 byte of ...

Resolution

To resolve this issue​​​, please ensure that in the schema test YAML file, you specify the result's p_event_time  in the following format:

p_event_time: YYYY-mm_ddTHH:MM:SS.fff Z

For example, 2:45:18.545 AM on Nov 21, 2022 would be written as 2022-11-21T02:45:18.545 Z.

Cause

A common mistake in pantherlog is to write the p_event_time result in the same format as the input timestamp. However, Panther has strict rules on the formatting of p_event_time, leading to the error as seen above.