Issue:
When the Policy Manager Server forwards event logs to the syslog server, the log comes in UTC time format. Can it be changed to the Policy Manager Server's operating system time format?
Resolution:
Regarding the syslog timestamp from Policy Manager Server — this is by design. Policy Manager Server always forwards event logs to the syslog server using UTC+0 timestamps, and there is currently no configuration option to change the timezone to local time (UTC+8 or any other).
As a workaround, we recommend configuring your syslog receiver or SIEM platform to apply a timezone offset when ingesting the logs. Most syslog solutions support converting UTC timestamps to a local timezone on the receiving side.
Article no: 000010661