|Applies To||RSA Product Set: Security Analytics|
RSA Product/Service Type: Security Analytics UI
Platform (Other): Checkpoint Smart Tracker
|Issue||When viewing a raw Checkpoint log in RSA Security Analytics, the time displayed may be different from that when viewing the event in the Checkpoint Smart Tracker.|
Checkpoint Logs (but in general most of security devices logs) are stored internally in UTC time on the system. When displayed in the Smart Tracker the time displayed for the event is calculated from the Timezone set for the Checkpoint system.
Here an example:
1) you can see here some log entries on the Checkpoint Smart Tracker. The time is in EST (UTC -5)
2) The same log entry highlighted in point 1) can be seen in the Security Analytics Investigator.
The entry is in UTC (EST +5) as you can see from the below screenshot
3) the time in the checkpoint itself is set in EST timezone, however the logs are generated in UTC
|Resolution||The checkpoint firewall (and most of security devices) generates logs in UTC|