Timestamps disagree across sources
Every source stamps time its own way, in its own zone, on its own clock. Correlation assumes they agree, and they usually do not.
Three sources record the same event. You get three different times.
The firewall writes local time with no zone marker. The endpoint agent writes UTC. The application writes whatever its own host believed the time was, and that host has not successfully synced since a reboot in March.
None of them is lying. They are answering slightly different questions.
There are also several clocks inside one record. When the thing happened. When
the source noticed it. When it was written to disk. When it arrived at your
platform. A search result showing you a single field called timestamp has
quietly picked one of those on your behalf, and it is frequently the last one.
So a timeline assembled by sorting on whatever the platform returns can put effect before cause. People catch that when it is absurd, a logon landing after the file it opened. Nobody catches a thirty second skew, and thirty seconds is enough to break a correlation rule with a tight window.
Two habits cover most of it. Store an unambiguous event time in UTC at ingest and keep the source’s raw value next to it. Then watch clock drift on your sources the same way you watch whether they are sending at all.
Take a recent case. Ask which field the timeline was sorted on, and whether every source in it meant the same thing by that field.
CHECK YOURSELF
A rule requires a logon and a process start within sixty seconds of each other. Both events are present in the data, every time, and the rule never fires. What is the most likely cause?
SHOW THE ANSWER
The two sources stamp time differently, so the measured gap is not the real one
Why. All four are real failure modes, and three of them fail loudly. A window that is genuinely too short fails inconsistently rather than never, a wrong field matches nothing at all and shows up the first time anyone tests it, and dropped events leave gaps visible elsewhere in that source. A zone or clock difference produces exactly this symptom instead: both events present, both correct, and a computed interval wrong by the size of the offset. Compare the two timestamps against one event you can find in both sources before you touch the window.