Hi,
I have a parent/client grouping set up. Many data sources are from different time zones in the US/Canada. If the parent has a time zone, does that mean that the client time zones must have the same time zone? I am able to modify the client time zone, but will that increase the time delta?
I noticed that it's possible to have the parent time zone blank - does that allow more flexibility for the client data sources and their respective time zones?
Thank you.
Solved! Go to Solution.
Most datasources log in UTC/GMT these days. It is rare to have a datasource that actually produces logs in the local time as being able to quickly match logs across global organisations has become more important.
That said, you can override the timezone setting on most client datasource configurations (this depends on the collector being used).
Changing the timezone will have no impact on the delta as long as the timezone setting is correct (i.e. after SIEM automatically adds/subtracts the timezone from the time in the event, the resulting UTC time is similar to the current time on the receiver).
Most datasources log in UTC/GMT these days. It is rare to have a datasource that actually produces logs in the local time as being able to quickly match logs across global organisations has become more important.
That said, you can override the timezone setting on most client datasource configurations (this depends on the collector being used).
Changing the timezone will have no impact on the delta as long as the timezone setting is correct (i.e. after SIEM automatically adds/subtracts the timezone from the time in the event, the resulting UTC time is similar to the current time on the receiver).
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA