Skip to main content
Question

Delay between ingestion and create alert

  • June 10, 2026
  • 3 replies
  • 54 views

bitshock1015
Forum|alt.badge.img+3

Hello, team

 

I’d like to understand the delay between when a case is created and when it’s detected. All cases based on CrowdStrike have a delay of 1 to 2 hours before the alert is generated.

 

Can this time be adjusted? Why does this only happen with CrowdStrike?

 

We have two SecOps consoles with different environments, and this delay only occurs on one of them; both have the same collection permissions.

 

 

3 replies

dnehoda
Staff
Forum|alt.badge.img+18
  • Staff
  • June 14, 2026

What you have shared here is saying that your event time happens after your rule triggers.  

 

event timestamp is 20:17:56 

detect timestamp is 17:18:00

 

This is impossible.    Are your tools setup all in the same time zones? 

 

 


dnehoda
Staff
Forum|alt.badge.img+18
  • Staff
  • June 14, 2026

Also to note, this rule by default runs every hour.    You would need to make a copy of this rule and make it custom if you wanted it to br near real time or every 10 mins.  


AymanC
Forum|alt.badge.img+14
  • Bronze 5
  • June 17, 2026

Hi ​@bitshock1015,

 

The below documentation may be of use:

 

Understand rule detection delays  |  Google Security Operations  |  Google Cloud Documentation

 

In particular, this will allow you to help analyze where the latency may be:

 

https://docs.cloud.google.com/chronicle/docs/detection/detection-delays#analyze-delays

 

Kind Regards,

Ayman