A few times in the past 1 1/2 - 2 years, we've had an escalation or incident come in. When we review it, the actual login time was 1-2 days before, or over 12 hours prior to the notifications.
When reaching out to SOC Support the answer is that Microsoft delays the logs sometimes and there isn't something they can do about it.
However, there should be something clear at the beginning that tells us the logs were delayed for that incident/escalation. Receiving an escalation for 9/13, for a suspicious sign in from 9/11 (for instance) is concerning and no reason is stated why.
Sending to support to ask why, the answer is "Microsoft logs were delayed". But that should be clear in the ticket itself as well.