Skip to main content

Ingestion latency

  • April 3, 2025
  • 2 replies
  • 53 views

Forum|alt.badge.img+8

Hello community , 
I'm facing a issue that my zscaler logs are ingested with a latency around 60 miutes and more.
The difference between ingested timestamp and event timestamp is around 560 minutes.
Who can tel this can be due to what exactly ? 
Thanks for help

2 replies

kentphelps
Staff
Forum|alt.badge.img+11
  • Staff
  • April 3, 2025

This post, while focus on timestamps,includes a detailed section on how to analyze latency (as well as time based misconfigurations) - https://medium.com/@thatsiemguy/fix-rfc3164-timestamps-with-bindplane-for-enterprise-fb96dd16d015

Also this doc: https://cloud.google.com/chronicle/docs/detection/timestamp-definitions



Forum|alt.badge.img+3
  • New Member
  • April 3, 2025

@Rached1996 How are you ingesting the logs currently?