industrial//industrial data layer//event time

Event time is the instant at which a measurement was taken or an event happened in the plant, as opposed to the instant a system received or stored it, and keeping the two apart is what lets an analysis put industrial data in the right order when links delay it. One value carries up to three clocks: the event time stamped at the source, the ingestion time at which the historian or database wrote it, and the business time that assigns it to a shift, a batch or a billing period.


Event time is the instant at which a measurement was taken or an event happened in the plant, as opposed to the instant a system received or stored it, and keeping the two apart is what lets an analysis put industrial data in the right order when links delay it. One value carries up to three clocks: the event time stamped at the source, the ingestion time at which the historian or database wrote it, and the business time that assigns it to a shift, a batch or a billing period.

On a healthy network the three agree to within milliseconds and nobody notices. They part when something buffers. A cellular link to a pumping station drops for forty minutes; the RTU keeps measuring and sends the backlog when the link returns. Every one of those forty minutes of readings now has an ingestion time of 10:41 and an event time spread from 10:01 to 10:40. A dashboard that plots by ingestion time shows a flat line, then a vertical burst; one that plots by event time shows what the pump did.

A reading is located in time by the clock of the thing that measured it, never by the clock of the thing that stored it.

Which is why the timestamp should be taken as close to the sensor as possible, travel with the value, and come from a synchronized clock.

The tag carries the event time as one of its three parts (value, timestamp, quality), and OPC UA goes further with a source timestamp and a server timestamp on every value, the two clocks made explicit. Plain Modbus carries neither: the reader stamps the value when it arrives, so a slow poll cycle quietly becomes timestamp error.

An event time is only as good as the clock behind it. Two PLCs whose clocks drift a few seconds apart can make an alarm appear to precede its cause; ordering events across devices needs time synchronization (NTP for seconds, PTP for microseconds).

MQTT guarantees delivery, never freshness: a message held by the broker during an outage arrives looking new unless its payload carries the event time and the subscriber checks its age before acting on it.

Business time is a rule over event time, never a third measurement. Readings taken at 21:59 belong to the afternoon shift even if they reach the database at 22:03; computing shift totals by ingestion time moves output from one crew to the next.

Late data forces a choice at the consumer: wait for stragglers before closing a window (and report later), or close on time and correct afterwards. A training table for predictive maintenance built by joining historian rows to work orders on ingestion time can put the symptom after the repair.