You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The normal timestamp change is now done in the t.normalizeEventCtxTimes processor function.
Later in the flow the packet timestamp is initialized using the event timestamp:
This problem was probably introduced when we moved the time change to support the process tree processor functions.
Anyways, we should probably just add a step in the network capture pipeline that calls the t.normalizeEventCtxTimes function.
Currently when capturing network packets into a
![image](https://private-user-images.githubusercontent.com/87267148/295862993-42052c8e-710f-432c-965f-952003cbbce5.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MTk2OTIzNTksIm5iZiI6MTcxOTY5MjA1OSwicGF0aCI6Ii84NzI2NzE0OC8yOTU4NjI5OTMtNDIwNTJjOGUtNzEwZi00MzJjLTk2NWYtOTUyMDAzY2JiY2U1LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNDA2MjklMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjQwNjI5VDIwMTQxOVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTc1YjIyOGY5NTA2NzVhMjk0OWRjN2VlMThiNDhlMTQ3MTZiOTQyMDI0MTY1NTk4YjViMjJkM2VlNzljMDRhNWEmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JmFjdG9yX2lkPTAma2V5X2lkPTAmcmVwb19pZD0wIn0.RxtXiT07HsUZd-7RoftFxB6sUG_swHAcXwiZ9zRkhQc)
pcap
file a relative time is given:This is done because the network events don't go through the normal pipeline, thus their timestamp isn't modified:
The normal timestamp change is now done in the
t.normalizeEventCtxTimes
processor function.Later in the flow the packet timestamp is initialized using the event timestamp:
This problem was probably introduced when we moved the time change to support the process tree processor functions.
Anyways, we should probably just add a step in the network capture pipeline that calls the
t.normalizeEventCtxTimes
function.Thanks to @oshaked1 for noticing it.
The text was updated successfully, but these errors were encountered: