How does a firewall of USG6000 V100R001C10/V100R001C20/V100R001C30 process the timestamps carried in logs?
The firewall processes timestamps in the logs of different types as follows:
When the firewall outputs session logs and service logs in dataflow format, the timestamps in the logs are fixed to the UTC timestamps by default. Upon receiving the logs, the LogCenter modifies the timestamps in the logs based on the local time zone to ensure that the time of the logs is consistent with the local time. Then, it displays the log information on the web-based pages. In this way, the log receiving time (local time of the LogCenter) and the time contained in the logs, displayed on the LogCenter, have no deviation.
When the firewall outputs service logs and system logs in syslog format, the timestamps in the log headers are fixed to the UTC timestamps by default.