Video Screencast Help
Search Video Help Close Back
to help

Security alert notification time issue

Created: 29 Jan 2013 | 12 comments
jd31's picture
0 0 Votes
Login to vote

Hey,

Looking at client logs of a SEP12 machine and there is an intrusion prevention application block of ntoskrnl.exe on the 29/01/2013 @ 13:07:45

When I look at the SEPM logs the same event is there but appears to be logging this security notification as occurring on 29/01/2013 @14:07:45

Any ideas why this event is reporting a different time between client and SEPM server? Any help would be good. Thanks.

 

Comments 12 CommentsJump to latest comment

pete_4u2002's picture

are the client and SEPM time set at the same timezone?

+1
Login to vote
Brian81's picture

Depends on your heartbeat. What is it set to? Clients check in to the SEPM based on this and will upload logs, get new policies, update content, etc.

+1
Login to vote
jd31's picture

Yeah that is what I thought at first, checking with the customer to see if the time on the server is correct.

Any other ideas? Thanks for the quick reply Pete.

0
Login to vote
jd31's picture

Ok cool, thanks for the replies. I will look into this now and come back when I have a solution. Thank you.

0
Login to vote
SebastianZ's picture

Either the timezone difference or differnce between log creation on the SEP client and entry created for it in SEPM DB - heartbeat 1 hour?

+1
Login to vote
jd31's picture

Hmmm, heartbeat set to five minutes and clients running in pull mode. Server time up to date and the same as client. Strange one this.
Any other info or thoughts would be great. Thanks.

0
Login to vote
AjinBabu's picture

If managed clients are in a different time zone from the management server, and you use the Set specific dates filter option, you may see unexpected results The accuracy of the data and the time on both the client and the management server may be affected. Look in to the following link

http://www.symantec.com/business/support/index?page=content&id=HOWTO81125&actp=search&viewlocale=en_US&searchid=1356593167096

-2
Login to vote
jd31's picture

Both client and server times are the same and your link doesn't work but thanks anyway.

0
Login to vote
pete_4u2002's picture

btw what timezone they are in i.e GMT +/-?
the link AjinBabu posted can be opened using the below url
http://www.symantec.com/business/support/index?pag...

0
Login to vote
jd31's picture

GMT +0:00 this is annoying, I can't find anything on it. Thanks

0
Login to vote
SebastianZ's picture

Not sure what to think of this - usually when we saw this problem it was cause by the timezone difference to the GMT time:

https://www-secure.symantec.com/connect/forums/not...

http://www.symantec.com/docs/TECH165766

+1
Login to vote