Created on 01-31-2024 12:55 AM Edited on 01-31-2024 03:19 AM By Jean-Philippe_P
This article describes how changing FortiAnalyzer's system time updates the Date/Time column in logs presented in Log View.
FortiAnalyzer.
The Date/Time column reflects the itime field in raw logs, the value of which indicates the time the log was received by FortiAnalyzer, as explained in the following KB article: Technical Note: Understanding FortiAnalyzer time-related fields in logs and SQL tables.
When changing FortiAnalyzer's system time, FortiAnalyzer will reset its local connection to the Postgres database with the new timezone as the connection's parameter.
As an example, the following FortiAnalyzer's system time is configured to Hong Kong time (GMT+8), and the logs Date/Time can be seen below:
The system time is then changed to Jakarta time (GMT+7), and the Date/Time column is changed accordingly:
Running the following debug command will show the Postgres connection being reset with the updated timezone:
diagnose debug application sqlplugind -1
diagnose debug enable
Related Article:
Technical Note: Understanding FortiAnalyzer time-related fields in logs and SQL tables
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.