Wednesday, June 22, 2011

Security Onion and UTC

Sguil uses UTC.  It does this for a few reasons:
  1. UTC avoids any timewarps when changing from standard time to daylight saving time and vice versa.
  2. UTC allows for correlation when sensors are in different time zones.
Because Sguil uses UTC, it is recommended to set your Security Onion timezone to UTC.  Here's how:
echo "Etc/UTC" | sudo tee /etc/timezone
sudo dpkg-reconfigure --frontend noninteractive tzdata
For more information, please see:

No comments:

Search This Blog

Featured Post

Quick Malware Analysis: SMARTAPESG / NETSUPPORT RAT / STEALC pcap from 2025-03-26

Thanks to Brad Duncan for sharing this pcap from 2025-03-26 on his malware traffic analysis site! Due to issues with Google flagging a warni...

Popular Posts

Blog Archive