Forum Discussion
Log Analytics workspace:TimeGenerated value Current time for less than 48hrs logs(From current time)
In azure portal, In log analytics workspace, we have DCR Based tables, in which we have TimeGenerated field which we set as part of body and inject using folllowing python call-
client.upload(rule_id=dcr_immutableid, stream_name=stream_name, logs=json.loads(body))
For TimeGenerated field which contains value less than 48hrs(from current time), for those logs it sets current timestamp. (It works for last 48 hrs TimeGenerated)
Expected behavior should be TimeGenerated value should accept all values.
1 Reply
Azure Monitor enforces strict rules for the TimeGenerated field values cannot be more than two days old at ingestion or more than one day in the future. If logs fall outside this window, Azure Monitor automatically replaces the timestamp with the actual ingestion time. This explains why your logs with TimeGenerated less than 48 hours from the current time are accepted, but older values are reset.
https://learn.microsoft.com/en-us/azure/azure-monitor/logs/log-standard-columns