Record and timestamp problem in audit.log

According to the bug you provided, it is not an issue/bug. Timestamp information in the audit log is always logged in UTC. The manual states this. The bug you linked is a feature request to have the audit timestamp be timezone sensitive. For now, the solution seems to have your qradar parse the timestamp in UTC and convert it on import.

3 Likes