000029333 - How to understand the difference between times displayed in Checkpoint Smart Tracker and event.time meta in RSA Security Analytics

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support Employee on Apr 21, 2017
Version 4Show Document
  • View in full screen mode

Article Content

Article Number000029333
Applies ToRSA Product Set: Security Analytics
RSA Product/Service Type: Security Analytics UI
Platform: CentOS
Platform (Other): Checkpoint Smart Tracker
IssueWhen viewing a raw Checkpoint log in RSA Security Analytics, the time displayed may be different from that when viewing the event in the Checkpoint Smart Tracker.
Checkpoint Logs (but in general most of security devices logs) are stored internally in UTC time on the system. When displayed in the Smart Tracker the time displayed for the event is calculated from the Timezone set for the Checkpoint system. 
Here an example:
1) you can see here some log entries on the Checkpoint Smart Tracker. The time is in EST (UTC -5)    
User-added image
2) The same log entry highlighted in point 1) can be seen in the Security Analytics Investigator. 
The entry is in UTC (EST +5) as you can see from the below screenshot

User-added image
3) the time in the checkpoint itself is set in EST timezone, however the logs are generated in UTC
User-added image
ResolutionThe checkpoint firewall (and most of security devices) generates logs in UTC