Environment
Carbon Black Cloud Console: All Versions
Carbon Black Cloud Sensor: All Versions
Question
Why are events and alerts showing with dates in the future?
Answer
- Caused by anomalous changes to the endpoint's system time which the sensor relies on to assign timestamps to events/alerts.
- Most commonly occurs when system time changes backwards then forwards
Additional Notes
The backend tries to account for this with a "sensor drift" calculation. In cases with potentially large time discrepancies on the endpoint, this results in pushing events into the future.