What's the meaning of each enriched timestamp field in my alerts on Panther?
Last updated: September 3, 2024
QUESTION
What is the meaning of each alert timestamp field in my alerts records on Panther?
ANSWER
Panther enriches each alert with the following timestamps:
p_alert_creation_timeis the first time an event matched this rulep_event_timeis the time the event reported itself as happeningp_parse_timeis the time the event was processed by Pantherp_alert_update_timeis the last time an event matched this rule (in the case of deduplication)