Hello,
During testing a custom rule, we are not able to test the rule against logs for the latest 4hours.
https://cloud.google.com/chronicle/docs/detection/manage-all-rules Point 8.
The end time available is 4hours ago.
Example: UTC Time: 6pm. Possiblity to select only 2pm as end time.
If I changed my preferred timezone to EST, I ‘ll also get a 4 hours delays.
Is it an expected behavior ?
Thanks
Solved
Custom rule - Run test - 4 hours delay
Best answer by chrisd2
Hello, this is definitely not expected behavior.
If it reoccurs, try to refresh the page, maybe the UI did not update as time passed ?
If it keeps occuring you’re good to open a support case, this is definitely weird.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
