cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7814
Views
5
Helpful
6
Replies

FTD 2130 - Changing the Syslog Time zone

dejan_jov1
Level 1
Level 1

Hi,

 

Our Firepower 2130 is sending Syslogs with Timestamps in UTC Time Zone and I can't find way how to change it.

I configured in Platform settings/Time Syncronization that the FTD updates its Time from Management Center but when I do show ntp on FTD I get this output:

 

> show ntp
NTP Server                : 127.127.1.1
Status                    : Unknown
Offset                    : 0.000 (milliseconds)
Last Update               : 99m (seconds)

NTP Server                : 127.0.0.2
Status                    : Being Used
Offset                    : 0.278 (milliseconds)
Last Update               : 29 (seconds)

 

Shouldn't tere be the FMCs IP?

On FMC under User Preference the Time Zone is CET.

 

show time on FTD:

 

> show time
UTC -       Fri Apr  6 13:53:30 UTC 2018
Localtime - Fri Apr 06 09:53:31 EDT 2018

 

Is it possibe to change the UTC Timestamps in Syslog messages to another Time Zone?

 

Thanks in Advance!

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

Is your FMC a VM? If so, it is not recommended to use it as an NTP server for the sensors.

 

Firepower syslog messages will always have UTC timestamps. It's not an option to change that.

View solution in original post

6 Replies 6

Marvin Rhoads
Hall of Fame
Hall of Fame

Is your FMC a VM? If so, it is not recommended to use it as an NTP server for the sensors.

 

Firepower syslog messages will always have UTC timestamps. It's not an option to change that.

Hi Marvin,

 

Our FMC is an VM, so we will need to use another NTP Server. Thanks!

Hi,

 

on FTD got timezone UTC (UTC+0:00), Device Management, its possible to change timezone.  bcus on the FMC, have correct timezone.

 

Thanks

Any news on this topic?

on my FMC 7.0 syslog messages are sent to syslog server in UTC format... kind of confusing.

@mariya.telitsina 

Cisco sees that as the "right" way to do it per the RFC so the behavior remains as-is.

Thank you Marvin for your reply! I googled a way to make an offset on a syslog server. will try this as a workaround.

 

Review Cisco Networking for a $25 gift card