Forum Discussion
NM_MS
Jun 24, 2024Copper Contributor
Filter on Timestamp not working with DeviceFileEvents/DeviceNetworkEvents
Hi I'm tryng to filter events in DeviceFileEvents from last week in a KQL query. But I'm experiencing strange behaviour. When I add the time range condition, it doesn't return any value. Am I ...
cyb3rmik3
Microsoft
Jul 06, 2024NM_MS hi!
Indeed this is strange. Have you recently unified Sentinel and XDR? Just asking as I can see the Timegenerated column is available. The only time I had this "glitch in the Matrix", was for a few days after I completed bringing XDR and Sentinel together. Have you tried to run the query using Timegenerated instead of Timestamp?