Hello! I just responded you but the message is not showing so, sorry if you get a repeated answer
About the logs timestamps, the first time is you manager's time when the event is received, the following times are your client's time when the log was created, to be sure, check the timezones in both systems using the command: ls -l /etc/localtime
The alert in the
conversation is a level 6 alert, you can see it on the opening tag:
<rule id="100008" level="6" frequency="3" timeframe="10">
Regards!