Good afternoon
Glad you are responding to this problem!
Currently, all Wazuh components are installed on one server - these are the components Wazuh Manager, Wazuh Dashboard, Wazuh Indexer, and including Filebeat.
Currently, when installing Debian 11 OS on my server, I indicated the current system time for my region.
Here are my settings and the current status of the time service:
- root@Wazuh-Server:/home/admin# timedatectl status
- Local time: Tue 2024-05-07 15:16:16 MSK
- Universal time: Tue 2024-05-07 12:16:16 UTC
- RTC time: Tue 2024-05-07 12:16:16
- Time zone: Europe/Moscow (MSK, +0300)
- System clock synchronized: yes
- NTP service: n/a
- RTC in local TZ: no
Perhaps the problem, of course, is that I have not updated the test server to the latest versions of packages for Debian 11 for a long time, since this is very critical for the entire system to work stably for a long time.
I'll try the task of including the
"deb.debian.org" repository in
"APT EDIT-SOURCES". I will update the system packages for Debian 11. And then I will inform you about this additionally!
I am also interested in your answer, which you indicated that depending on the logs received, the time for receiving events from the logs is indicated for them. But if for some third-party systems I can still understand this nuance, then for Wazuh daemons and even more so for system logs, in my opinion, this is critical when the time of receiving logs goes several hours ahead of the real current time.
Once again I will duplicate the settings in Wazuh “Menu” -> “Stack Management” -> “Advanced Settings”:
- Time zone for date formatting = Browser
- Formatting locale = Russian
вторник, 7 мая 2024 г. в 11:52:33 UTC+3, Juan Antonio Garcia Ruiz: