Quantcast
Channel: Questions in topic: "heavy-forwarder"
Viewing all articles
Browse latest Browse all 727

How do I configure my heavy forwarders to parse the timestamp for a WinRegistry sourcetype?

$
0
0
Hello I'm having an issue with timestamping for my WinRegistry data. I don't know whether by design, or for some other reason, the timestamp in the logs are as such: 11/02/11154 14:24:53.046 which of course is interpreted incorrectly. These Universal Forwarders forward to a cluster of Heavy Forwarders where an app SHOULD set the timestamp: [WinRegistry] DATETIME_CONFIG = CURRENT but this does not seem to be the case as I have logs that go back to 1969 and forward to 2032. Any ideas on where the issue may be? Thanks for the thoughts

Viewing all articles
Browse latest Browse all 727

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>