Client is streaming CASB Investigate logs to S3 bucket and then to Splunk.
In raw exported logs client sees two time fields - device_time and log_time in Unix time format and asks what the difference is, what does each time represent?
Which one is the time when the event happened?
INFRA Engineering responded with clarification:
Engineering also provided link to schema section, recently added to the CASB Streaming Logs Tech Doc, which provides additional details: