Snort mailing list archives

Re: You caught them, what next?


From: Jason Haar <Jason.Haar () trimble co nz>
Date: Fri, 4 Apr 2003 10:54:24 +1200

On Thu, Apr 03, 2003 at 01:02:15PM -0600, bmcdowell () coxhealthplans com wrote:
But I think the point being made was, that's not what they wanted to
hear.  Whether UTC or Central time, once you know what time zone the
logs are in, you can adjust accordingly.  I believe he said they wanted
that information in the logs themselves.  Presumably, so the

I'm sorry if I'm missing the blindingly obvious here - but why don't you
just EDIT your logs to include the timezone before you send it to them?

You know:

Apr  4 10:52:25 srv snort: ...

becomes

Apr  4 10:52:25 NZST srv snort: ...


wouldn't that do? 

Just what is the problem you are trying to solve?

-- 
Cheers

Jason Haar
Information Security Manager, Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1


-------------------------------------------------------
This SF.net email is sponsored by: ValueWeb: 
Dedicated Hosting for just $79/mo with 500 GB of bandwidth! 
No other company gives more support or power for your dedicated server
http://click.atdmt.com/AFF/go/sdnxxaff00300020aff/direct/01/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: