Security Compliance

SEM insertion time and detection time

This article explains how SEM displays events from different time zones that do not use UTC.

First published date

5/8/2019 3:52 PM

Last published date

6/4/2020 8:37 AM

Overview

How Security Event Manager (Formerly Log & Event Manager) displays events from different time zones that do not use UTC.

Product section

Security Event Manager

Cause

Events on endpoints using local time as opposed to UTC time and SEM in different time zone.

Resolution

Ideally, all events should be in UTC. But in the case of monitoring events from one time zone, and using a SEM web console in another time zone, SEM will account for the time in the console and add or subtract the difference to/from the events insertion times. This can lead to confusion with insertion time and detection time being an exact amount of the hour difference.

The examples below show several different time zones. The minutes will normally be the same, seconds might have a small difference, and the hour will be the difference in time zone: 

UTC + 4: 

  • Insertion time: 17:23:31 pm
  • Detection time: 13:23:29 pm
UTC - 4:
  • Insertion time: 09:23:31
  • Detection time: 13:23:29
UTC + 8
  • Insertion time: 21:23:31
  • Detection time: 13:23:29
If neither are set to UTC, the detection and insertion time would be the time difference between the two time zones.

How to change Time zone in SEM: 
cmc::appliance > tzconfig
Also, please note when changing the Timezone in SEM or DateTime it may need a restart of the SEM manager for the changes to take effect. 
cmc > manager > stop
cmc > manager > start