What is the meaning of each alert timestamp field in my alerts records on Panther?
Panther enriches each alert with the following timestamps:
p_alert_creation_time
is the first time an event matched this rule
p_event_time
is the time the event reported itself as happening
p_parse_time
is the time the event was processed by Panther
p_alert_update_time
is the last time an event matched this rule (in the case of deduplication)