Quantcast
Channel: Symantec Connect - Products
Viewing all articles
Browse latest Browse all 21587

SEP Event Time and Block Times are different

$
0
0
I need a solution

On the Network Threat alerts that I am getting the event time and the time in the event description of the time an IP will be blocked are different. For example, in one alert the event time was 2/18/2015 18:11:04 and in the event description it says "The client will block traffic from IP address x for the next 600 seconds (from 2/18/2015 4:12:41 PM to 2/18/2015 4:22:41 PM)" 4:12 PM would be 16:12 which is 2 hours prior to the event time... if only SEP could go back in time and block. At first I thought maybe one time is SEPM and the other is the system time on the client but why would it be setup that way? Another alert I got today has an event time of 2/27/2015 12:54:18 and the event description is, "The client will block traffic from IP address x for the next 600 seconds (from 2/27/2015 12:15:56 PM to 2/27/2015 12:25:56 PM)" which is a difference of approximately 40 minutes. Where are these two time metrics coming from and why would they be different especially why would they be off by 40 minutes which seems like an odd number? Thanks.


Viewing all articles
Browse latest Browse all 21587

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>