You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The misp.event.publish_date field is being interpreted incorrectly by Elasticsearch. A raw value of 1685972314 is represented as "1970-01-20T12:19:32.314Z". It should be 2023-06-06T14:17:34Z.
The issue here seems to be seconds versus milliseconds since the epoch. The value was being left as an integer timestamp and stored in a date field, which Kibana then presents as a millisecond timestamp. See the PR for details of the change.
For reference, the interpretation proposed in the issue description seems slightly off, perhaps due to a cut and paste error:
raw: 1685972314
current: 1970-01-20T12:19:32.314Z (UNIX timestamp in milliseconds)
proposed: 2023-06-06T14:17:34.000Z
adopted: 2023-06-05T13:38:34.000Z (UNIX timestamp in seconds, 1 day 39 minutes earlier than proposed)
The
misp.event.publish_date
field is being interpreted incorrectly by Elasticsearch. A raw value of1685972314
is represented as "1970-01-20T12:19:32.314Z". It should be2023-06-06T14:17:34Z
.Event
The text was updated successfully, but these errors were encountered: