Dec 05 2023 06:42 AM
Hi,
I'm facing a weird issue where TimeGenerated value is inaccurate when we use the query condition | where TimeGenerated >= ago()
See here:
As you can see above, the time is in future time compared to my local time at the right bottom.
But if i use | where TimeGenerated between()
or if i use the portal GUI Time Range, it able to return the correct TimeGenerated value:
We notice this issue after the Linux Log Relay server timezone was changed from JST to UTC, then changed back to JST again.
The server has been rebooted 3 times, which i believe the rsyslog and the ama services would take effect on the changes of timezone as well.
Urgently need advise on this as it will certainly disrupt our Analytic Rule as well as Hunting query.
Dec 08 2023 12:21 PM
Dec 10 2023 01:00 AM
@BillClarksonAntill We using AMA. The link you posted was for legacy LAA.
Any way issue was resolved after the Log Relay Server where the AMA was installed is rotated and started fresh without any localtime under UTC.