IntegralDefense / ACE

Analysis Correlation Engine
Apache License 2.0
26 stars 10 forks source link

time default for alert filtering does't agree with alert time #157

Closed seanmcfeely closed 5 years ago

seanmcfeely commented 5 years ago

If you change the filter to all see all alerts in the last seven days, the date field defaults to eastern time.

filter: alert received between 2019-01-19 00:00:00 and 2019-01-25 13:27:00 AND with observable type snort_sig value b'2019182'

seanmcfeely commented 5 years ago

basically, the filter seems to default to eastern time and thus doesn't display a five hour window of alerts. Should we default display alerts in the user's time zone instead of UTC??

unixfreak0037 commented 5 years ago

basically, the filter seems to default to eastern time and thus doesn't display a five hour window of alerts. Should we default display alerts in the user's time zone instead of UTC??

Yes I think that'd be reasonable.