How to resolve "EventTime: DecodeTime" parsing error when testing schemas with pantherlog
When testing a schema with pantherlog, you get an error of the following form:
EventTime: DecodeTime: parsing time "..." as "...": cannot parse "..." as "...", error found in #10 byte of ...
To resolve this issue, please ensure that in the schema test YAML file, you specify the result's
p_event_time in the following format:
p_event_time: YYYY-mm_ddTHH:MM:SS.fff Z
For example, 2:45:18.545 AM on Nov 21, 2022 would be written as
A common mistake in pantherlog is to write the
p_event_time result in the same format as the input timestamp. However, Panther has strict rules on the formatting of
p_event_time, leading to the error as seen above.