Document toolboxDocument toolbox

About the lhub_ts column

lhub_ts is a special column that is inserted to the events ingested from Event Types. lhub_ts stands for Devo SOAR Timestamp. It denotes the times at which the events happened.

When the events are ingested from Splunk or Sumo Logic, the lhub_ts values are set to milliseconds from the epoch. If you use a file-based connection, you have the ability to set that value in your file data. The value should also be in millisecond to ensure correct behavior in your flows.

In the UI, when it is detected that the value in lhub_ts is not in milliseconds, a warning will be shown in the node table.