Environment
- Carbon Black Cloud Event Forwarder API
Question
- When are timestamps used in PID values for API results determined?
Answer
Time stamp values are set from process start
Additional Notes
When gathering API data the process fields may show as similar to below
123-1610280010-1
In these cases the first section is the PID for the Process in question. The second portion is the Epoch Timestamp for when the Process started. This example is for January 10th, 12:00:10 PM GMT, but can show for Events at later dates.
Related Content