Forum Discussion
NM_MS
Jun 24, 2024Copper Contributor
Filter on Timestamp not working with DeviceFileEvents/DeviceNetworkEvents
Hi
I'm tryng to filter events in DeviceFileEvents from last week in a KQL query. But I'm experiencing strange behaviour.
When I add the time range condition, it doesn't return any value.
Am I doing something wrong?
Do you have any ideia what the problem migth be?
Thanks in advance
NM
- cyb3rmik3Iron Contributor
NM_MS hi!
Indeed this is strange. Have you recently unified Sentinel and XDR? Just asking as I can see the Timegenerated column is available. The only time I had this "glitch in the Matrix", was for a few days after I completed bringing XDR and Sentinel together. Have you tried to run the query using Timegenerated instead of Timestamp?