Security alert notification time issue
Created: 29 Jan 2013 | 12 comments
Hey,
Looking at client logs of a SEP12 machine and there is an intrusion prevention application block of ntoskrnl.exe on the 29/01/2013 @ 13:07:45
When I look at the SEPM logs the same event is there but appears to be logging this security notification as occurring on 29/01/2013 @14:07:45
Any ideas why this event is reporting a different time between client and SEPM server? Any help would be good. Thanks.
Discussion Filed Under:
Comments 12 Comments • Jump to latest comment
are the client and SEPM time set at the same timezone?
Cheers!
Pete
Help Link: http://www.symantec.com/business/support/overview.jsp?pid=54619
HI,
Check this thread may be help
https://www-secure.symantec.com/connect/forums/notification-using-gmt-instead-local-time-zone
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
Depends on your heartbeat. What is it set to? Clients check in to the SEPM based on this and will upload logs, get new policies, update content, etc.
SEP Knowledge Base
Endpoint SWAT
Yeah that is what I thought at first, checking with the customer to see if the time on the server is correct.
Any other ideas? Thanks for the quick reply Pete.
Ok cool, thanks for the replies. I will look into this now and come back when I have a solution. Thank you.
Either the timezone difference or differnce between log creation on the SEP client and entry created for it in SEPM DB - heartbeat 1 hour?
Hmmm, heartbeat set to five minutes and clients running in pull mode. Server time up to date and the same as client. Strange one this.
Any other info or thoughts would be great. Thanks.
If managed clients are in a different time zone from the management server, and you use the Set specific dates filter option, you may see unexpected results The accuracy of the data and the time on both the client and the management server may be affected. Look in to the following link
http://www.symantec.com/business/support/index?page=content&id=HOWTO81125&actp=search&viewlocale=en_US&searchid=1356593167096
Both client and server times are the same and your link doesn't work but thanks anyway.
btw what timezone they are in i.e GMT +/-?
the link AjinBabu posted can be opened using the below url
http://www.symantec.com/business/support/index?pag...
Cheers!
Pete
Help Link: http://www.symantec.com/business/support/overview.jsp?pid=54619
GMT +0:00 this is annoying, I can't find anything on it. Thanks
Not sure what to think of this - usually when we saw this problem it was cause by the timezone difference to the GMT time:
https://www-secure.symantec.com/connect/forums/not...
http://www.symantec.com/docs/TECH165766
Would you like to reply?
Login or Register to post your comment.