FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
FortiKoala
Staff
Staff
Article Id 190325
Description

Event timestamp does not match the timestamp when an alert is fired


Scope

FAQ


Solution

Problem

I have alerts getting fired, but the timestamp on the events don't always correspond to when the alert gets fired.


For example, when I search for an alert being triggered between 6pm and midnight on 27th February, the alert details show an event that happened around 1:45pm:



Solution

The alert is showing the correct information.


This happens when an agent has been offline and not able to stream event data to ZoneFox, for example a laptop has been off the network, so event data has been stored locally in the agents offline database.  When the agent has come online again, e.g. the laptop is back on the network, the event data has been uploaded to the ZoneFox server - and where applicable, an alert has been triggered at that time.  Hence events from an earlier date or time can be listed for an alert being triggered at a later time.

The agent is designed to store data when offline, so no events are ever lost.



Contributors