cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3356
Views
0
Helpful
1
Replies

Two different times in MARS Raw Logs.

dec0dernyc
Level 1
Level 1

Can someone please explain why I see two different time stamps in my MARS Raw Logs below for incidents.

Here is a copy of one of our raw logs. I changed some info.

8816265728ÿ05/07/2013 17:00:01ÿfirewallASA1ÿ0.0.0.0ÿ64823ÿ10.*.*.*ÿ636ÿ6ÿ<156>May 07 2013 21:00:01: %ASA-4-106023: Deny tcp src ABC_DEF:Something/65555 dst My_Network:10.*.*.*/636 by access-group "groupnamehere" [0x9191bd7, 0x0]

1 Reply 1

dec0dernyc
Level 1
Level 1

Can it be that MARS is set to EST and that the firewall is set to GMT.

Which makes sense being that EST is -4hours.

Just a thought.