Este documento explica os carimbos de data/hora comuns para eventos e detecções.
Para mais informações sobre carimbos de data/hora, consulte Função de data.
Os seguintes carimbos de data/hora estão relacionados a eventos:
Carimbo de data/hora do evento: momento em que um evento ocorreu e foi armazenado no campo metadata.event_timestamp
UDM. As regras e as pesquisas de UDM usam o campo metadata.event_timestamp para consultas.
Carimbo de data/hora da coleta: momento em que um evento foi coletado pela infraestrutura de coleta local, como o encaminhador. Isso é armazenado no campo metadata.collected_timestamp
da UDM.
Carimbo de data/hora ingerido: horário em que um evento foi ingerido pelo Google Security Operations.
Isso é armazenado no campo metadata.ingested_timestamp da UDM.
Os seguintes carimbos de data/hora são armazenados com as detecções:
Janela de detecção: para regras com uma seção match, uma detecção é criada no período, chamada de janela de detecção. Os carimbos de data/hora dos eventos que acionaram a detecção
estão dentro da janela de detecção.
Carimbo de data/hora da detecção: para regras com uma seção match, o carimbo de data/hora da detecção é o horário de término da janela de detecção. Caso contrário, o carimbo de data/hora da detecção será o metadata.event_timestamp do evento que gerou a detecção.
Carimbo de data/hora da criação da detecção: data e hora em que a detecção foi criada pelo mecanismo de detecção.
Onde os carimbos de data/hora aparecem no aplicativo
As seções a seguir definem onde você pode ver esses carimbos de data/hora na UI.
Visualizador de eventos da UDM
Para abrir a visualização Evento da UDM, faça o seguinte:
[[["Fácil de entender","easyToUnderstand","thumb-up"],["Meu problema foi resolvido","solvedMyProblem","thumb-up"],["Outro","otherUp","thumb-up"]],[["Difícil de entender","hardToUnderstand","thumb-down"],["Informações incorretas ou exemplo de código","incorrectInformationOrSampleCode","thumb-down"],["Não contém as informações/amostras de que eu preciso","missingTheInformationSamplesINeed","thumb-down"],["Problema na tradução","translationIssue","thumb-down"],["Outro","otherDown","thumb-down"]],["Última atualização 2025-08-21 UTC."],[[["\u003cp\u003eThis document details the various timestamps associated with events and detections within Google Security Operations, including their definitions and locations in the user interface.\u003c/p\u003e\n"],["\u003cp\u003eEvent timestamps mark when an event occurred, collected timestamps indicate when the event was gathered by local infrastructure, and ingested timestamps show when the event entered Google Security Operations.\u003c/p\u003e\n"],["\u003cp\u003eDetections have a detection window that is the time range in which events that trigger a detection are included, as well as a detection timestamp representing the end time of the detection window.\u003c/p\u003e\n"],["\u003cp\u003eThe detection created timestamp indicates when the detection was generated by the detection engine and can be found in the alert details pane under the created field.\u003c/p\u003e\n"],["\u003cp\u003eTimestamps for events (event and ingested) are visible in the UDM event viewer, while detection timestamps and event timestamps are in the Detections panel.\u003c/p\u003e\n"]]],[],null,["# Timestamp Definitions\n=====================\n\nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n\nThis document explains common timestamps for events and detections.\nFor more information about timestamps, see [Date function](/chronicle/docs/reference/parser-syntax#date_function).\n\nThe following timestamps are related to events:\n\n- **Event timestamp** : Time when an event occurred and is stored in the `metadata.event_timestamp` UDM field. Rules and UDM searches use the `metadata.event_timestamp` field for queries.\n- **Collected timestamp** : Time when an event was collected by the local collection infrastructure, such as the forwarder. This is stored in the `metadata.collected_timestamp` UDM field.\n- **Ingested timestamp** : Time when an event was ingested by Google Security Operations. This is stored in the `metadata.ingested_timestamp` UDM field.\n\nThe following timestamps are stored with detections:\n\n- **Detection window** : For rules with a [`match` section](/chronicle/docs/detection/yara-l-2-0-syntax#match_section_syntax), a detection is created over the time range, called the *detection window*. The event timestamps for events that triggered the detection are within the detection window.\n- **Detection timestamp** : For rules with a `match` section, the detection timestamp is the end time of the detection window. Otherwise, the detection timestamp is the `metadata.event_timestamp` of the event that generated the detection.\n- **Detection created timestamp**: Date and time the detection was created by detection engine.\n\nWhere timestamps appear in the application\n------------------------------------------\n\nThe following sections define where you can view these timestamps in the UI.\n\n### UDM Event viewer\n\nTo open the **UDM Event** view, do the following:\n\n1. Perform a UDM Search.\n2. In the **Events** tab, select an event to open the [Event viewer](/chronicle/docs/investigation/udm-search#event-viewer)\n3. The **UDM event** pane displays the following data:\n\n - Event timestamp is stored in the `metadata.event_timestamp` UDM field (1).\n - Ingested timestamp is stored in the `metadata.ingested_timestamp` UDM field (2).\n\n### Detections panel\n\nTo open the **Detections** view, do the following:\n\n1. Open **Detections** \\\u003e **Rules \\& Detections** , and then click the **Dashboard** button.\n2. Click the rule name link under the **Rule name** column. The **Detections** panel appears and displays the following:\n\n - Detection timestamp appears in rows that identify a detection (1).\n - Event timestamp appears in rows that identify events (2).\n\n### Alert view\n\nTo open the **Alert** view, do the following:\n\n1. Open **Detections** \\\u003e **Alerts \\& IOCs**.\n2. Under the **Alerts** tab, click the alert name link in the **Name** column.\n3. Click the **Overview** tab to display the following:\n\n - Alert (or Detection) created timestamp appears in the **Alert Details** pane \\\u003e **Created** field (1).\n - Detection window appears in the **Detection Summary** pane \\\u003e **Detection window** field (2).\n - Detection timestamp appears is in the **Detection Summary** pane \\\u003e **Alerts detected at** field (3).\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]