Wednesday, June 22, 2011

Security Onion and UTC

Sguil uses UTC.  It does this for a few reasons:
  1. UTC avoids any timewarps when changing from standard time to daylight saving time and vice versa.
  2. UTC allows for correlation when sensors are in different time zones.
Because Sguil uses UTC, it is recommended to set your Security Onion timezone to UTC.  Here's how:
echo "Etc/UTC" | sudo tee /etc/timezone
sudo dpkg-reconfigure --frontend noninteractive tzdata
For more information, please see:

No comments:

Search This Blog

Featured Post

Coming soon to Security Onion: Local IP Lookups!

Our upcoming Security Onion 2.4.120 release includes a new local IP lookup feature! This allows you to define local descriptions for importa...

Popular Posts

Blog Archive