Jan 2, 2024
An old challenge that most users have no idea about. Below my takes, from 2016:
https://opstune.com/2016/12/13/siem-tricks-dealing-with-delayed-events-in-splunk/
https://opstune.com/2017/06/01/its-about-time-to-change-your-correlation-searches-timing-settings/
I also wrote about similar issue with MS Sentinel: