When examining lime fields on Event Information, which one represents the time QRadar received the raw event?
The 'Start Time' timestamp represents when an event is received by a QRadar Event Collector, marking the moment QRadar first becomes aware of the event. This is crucial for understanding the timing of event processing and potential delays in the event pipeline.
Ruth
8 days ago