Previous Menu Next
Event Creation Time

Many ECS correlation operations work best when the engine can determine event creation time.

When an event is decoded, the engine adds header information to the event. This information is separate from the event's actual attributes, and is used for internal engine purposes. Header information consists of items such as the time the event entered the engine, a unique identifier for the event, and the creation time of the event.

The engine can be told how to derive event creation time from the event attributes via the optional create_time MDL expression. If create_time is not specified in the MDL definition, the engine uses the arrival time of the event at the engine in the create time header attribute. The create_time can also be overridden in the event I/O API EIO_sendEvent() function call.

The create_time expression can only appear in the syntax section of an event definition.