Hello Team,
Hope you are doing well.
I have one question regarding events. There are two time fields: one is pre-decoded time and the other is timestamp. Could you please provide some insight into the difference between these two?

Regards,
Chandra

Hello Nazmur,
so you say that the time difference is due to a mismatch in time standards—UTC (default time for the agent) and IST (used by the Wazuh manager)?
Is there a possibility to align the time settings so that the raw logs are also recorded in IST on the manager side? The current time difference is creating confusion during event analysis.
Please let me know if this can be adjusted.
Regards,