Appearance
system-audit.format.date-time
Refused 400 schemaNot an RFC 3339 date-time, in the system-audit payload schema.
| Outcome | Refused, 400 |
| Source | schema: The SOM 1.0 JSON Schema says no. The message is not valid SOM 1.0. |
| Checked at | SOM envelope, version and payload (see the order of checks) |
| Applies to | messages whose payload is checked against the system-audit schema |
What it means
The message breaks the system-audit payload schema. Not an RFC 3339 date-time. Typical cause: "2026-09-24 14:00", or a time with no time zone.
How to fix it
Send e.g. 2026-09-24T14:00:00Z: a T, seconds and a zone (Z or an offset). path in the violation points at the field.
Branch on the rule id, never on the violation's message text. All rules: rule catalogue.