08-21-2019 10:31 AM
The Ironport text logs on the Cisco Email Security Appliance have timestamps that go down to the second, but not the millisecond - like this:
Tue Aug 20 16:57:21 2019
This can make things very confusing when you send the logs to a SIEM: each event can have multiple associated log entries with the exact same timestamp, which can cause the order to get mixed up in the SIEM.
Is there any way to include ms in the log events?
08-21-2019 10:48 AM
08-21-2019 10:51 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide