# Clarification on using "timestamp\_override: event.ingested" with EQL sequence rules

**URL:** <https://discuss.elastic.co/t/clarification-on-using-timestamp-override-event-ingested-with-eql-sequence-rules/385377>\
**Category:** Elastic Security\
**Tags:** detection-rules\
**Created:** [March 9, 2026, 11:22am UTC](https://discuss.elastic.co/t/clarification-on-using-timestamp-override-event-ingested-with-eql-sequence-rules/385377 "2026-03-09T11:22:02Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![iremtoru](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iremtoru/32/140807_2.png) [@iremtoru](https://discuss.elastic.co/u/iremtoru)\
**Post date:** [March 9, 2026, 11:22am UTC](https://discuss.elastic.co/t/clarification-on-using-timestamp-override-event-ingested-with-eql-sequence-rules/385377/1 "2026-03-09T11:22:02Z")

</div>

Hello,

I’m looking for clarification and guidance around the use of `timestamp_override: event.ingested` in EQL sequence rules.

From my understanding and search of official docs:

- `timestamp_override: event.ingested` is recommended for many detection rules to handle delayed or backfilled data.

- However, it seems not recommended (or intentionally avoided) for EQL sequence rules, as sequences rely on correct event ordering and `maxspan` semantics based on _event time_, not ingest time.

My questions are:

1. Why exactly is `timestamp_override: event.ingested` discouraged for EQL sequence queries?  
Is it mainly due to ordering issues, `maxspan` misalignment, or risk of false positives?

2. Does this restriction depend on log source characteristics?  
For example, would data sources with near‑real‑time ingestion still be unsafe, or is the recommendation universal?

3. What is the preferred approach for EQL sequence rules when dealing with delayed ingestion?

Any explanation or best‑practice guidance for designing better EQL sequence rules across different data sources would be very helpful.

Thanks in advance!
