|
I have many hosts with the correct event time, these all forward to two receivers with the correct time. I wanted to search by "date_hour" to show after hour events. I notice that the "date_hour" is reporting 5 hours in the future on all hosts and events. Where is this time stamp coming from? Can it be synchronized? I am reporting on /var/log/audit/audit.log using souretype=linux_audit. |
|
|
|
I have a similar problem. The even logs have a certain GMT +11 correction and I need to match the two timestamps and I need no correction. Which file do I need to modify so that the two timestamps corresponding to one event (from a search) match(and without any GMT corrections) ?? Bit of urgency, would appreciate a quick help ! |