Map device receipt time -> End time
You may use map files on the connector but if you do that you will not be able to detect Time Issue.
Why you want to do this mapping?
If you have a huge difference it is maybe an useful information to take into consideration.
Now if it is short time, you may use Time Correction feature in Connector configuration.
I hope this information will be helpful.
Thank you for the reply.
We install a non supported connector and there is a issue on mapping the timestamps.
This is a temporary fix until the supported version is released.
Do you know how do I use the properties map to do this?
Thank you in advance.
You have to modify the map.0.properties file placed in /ARCSIGHT_HOME$/Curent/user/agent/map directory
with the correct.
Maybe this will work in replacing <device vendor of the connector> by the correct value without <>.
<device vendor of the connector>,deviceReceiptTime
Do not forget to restart the connector and check in agent.out.wrapper.log for this ERROR
If it is not working, You need to use set.expr, I can try to provide you a proper answer tomorrow.
If it is urgent, you may check in the Flex Dev Guide PDF, there are some pages about that.
Could you please try in map.0.properties
You have to restart the connector to permit this to work or to use the console to reload map files.
You have asked for deviceReceiptTime!
With agentReceiptTime it is not possible because the agentTime arrive after the parsing of events.
Could you please show endTime and deviceReceiptTime to see if there are not equal?