How do I manage time zone differences when firewalls and management stations are located in different time zones?


This article applies to:

  • Security Reporting Center 2.X
  • WebTrends Firewall Reporting Center 1.X
  • WebTrends Firewall Suite 4.X

Question:

How do I manage time zone differences when firewalls and management stations are located in different time zones?

Symptoms:

  • Check Point firewalls and management stations are in multiple time zones.

Procedure:

Set all management stations and firewalls, in all time zones, to GMT. Otherwise, the log file data will have time zones relative only to the local machine where the log files are written. This occurs whether the log file data is obtained from OPSEC LEA or the log export utility.

Notes:

In some cases, the individual records in a Check Point Firewall-1/VPN-1 log file are written out of chronological order. Because of how the records are read during analysis, if the sequencing is too far out of order log file processing will likely fail.

If the various log data has varying time stamps, the log file entries are recognized as being out of order, the analysis of the log file is prevented.

This article was previously published as:
NETIQKB1031

Last Modified 3/8/2006.
https://support.trustwave.com/kb/KnowledgebaseArticle10401.aspx