Skip to content

Conversation

@gbuisson
Copy link
Contributor

Add three new optional ObservedTime fields to the Sighting schema:

  • activity_interval: time when malicious activity occurred
  • detection_interval: time when activity was detected by source engine
  • modification_interval: time when sighting record was created/updated

Closes XDR-41654

Add three new optional ObservedTime fields to the Sighting schema:
- activity_interval: time when malicious activity occurred
- detection_interval: time when activity was detected by source engine
- modification_interval: time when sighting record was created/updated

Closes XDR-41654
Copy link
Contributor

@msprunck msprunck left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@gbuisson gbuisson changed the title Add time interval fields to Sighting entity Add new time interval fields to Sighting entity Nov 28, 2025
@gbuisson gbuisson merged commit e13bc52 into master Nov 28, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants