Created on 10-10-2016 12:45 AM Edited on 04-20-2022 12:29 PM By Anonymous
Description
AccelOps supports 3 different time attributes in parsed events.
These are set based on the following:
Time attributes are stored in Unix Epoch Time. Epoch Time is the number of seconds that have elapsed since midnight Coordinated Universal Time (UTC). The Coordinated Universal Time is the number a seconds which have elapsed since January, 1st of 1970 at 00:00.
Ex. 16:25:15 CET and 15:25:15 UTC will be translated and stored as 1358263515.
Currently timezone is not read from time field in device event so it is assumed to be in the timezone of the collector or super, whichever received the event.
When an event is viewed in a web browser via the AO UI, the various Time Attributes are adjusted to the current timezone of the computer you are running the web browser on. So if the event time attributes are in UTC but your laptop is in PST then all the time attributes are converted from UTC to PST in the UI.
if you export events from the AO UI the time attributes are converted to the timezone of the Super.
All
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.