Skip to main content

Regarding Data Visualization

  • January 30, 2025
  • 2 replies
  • 10 views

Forum|alt.badge.img+1

Hi Community,

I wanted to create a visualization of the meantime to detect. (Alert created timestamps - event timestamps) Do we have any resources that can help me with this? I can get the detection.commit_timestamp, which is when the alert was created, but I’m unable to get the case event timestamps.

I tried using detection.detection_timestamp Time, but it appears to be the time of the detection window. 

2 replies

cmorris
Staff
Forum|alt.badge.img+10
  • Staff
  • January 30, 2025

Can you try detection.created_time.seconds? That should be actual detection creation, rather than time window.


rajukg11
Staff
Forum|alt.badge.img+6
  • Staff
  • January 30, 2025

Unfortunately the relationship between the events and detections is not exposed in BQ.  The best you can do in BQ is to compare the detection.time_window.end_time.seconds with the detection.commit_timestamp.seconds.