Closed seanmcfeely closed 5 years ago
basically, the filter seems to default to eastern time and thus doesn't display a five hour window of alerts. Should we default display alerts in the user's time zone instead of UTC??
basically, the filter seems to default to eastern time and thus doesn't display a five hour window of alerts. Should we default display alerts in the user's time zone instead of UTC??
Yes I think that'd be reasonable.
If you change the filter to all see all alerts in the last seven days, the date field defaults to eastern time.
filter: alert received between 2019-01-19 00:00:00 and 2019-01-25 13:27:00 AND with observable type snort_sig value b'2019182'