Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is the difference between event time and ingestion time?

Event time is created by the source to represent when activity occurred; ingestion time is created by a receiving platform when the record arrived or was processed.

Delay is expected, not exceptional

Local storage, batching, collectors, outages, APIs and platform load can separate the fields by seconds or hours. Event time supports source chronology; ingestion time shows monitoring awareness. The source clock can be wrong and the platform can also delay or convert time.

Keep clocks and stages explicit

Preserve both values, creators, zones and processing metadata and establish buffering and forwarding route. Do not mix one system's source time with another's ingestion time without documenting the difference.

A cluster ingested together can reflect delayed delivery rather than simultaneous conduct.

The point to remember

Event and ingestion times answer different questions, and their gap can materially change the reconstructed sequence.

Reference: LOG-049Logs, Records & Provider Evidence