Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Carbon Black Cloud: Why are events and alerts showing with date/time in the future?

Carbon Black Cloud: Why are events and alerts showing with date/time in the future?

Environment

Carbon Black Cloud Console: All Versions
Carbon Black Cloud Sensor: All Versions
 

Question

Why are events and alerts showing with dates in the future?

Answer

  • Caused by anomalous changes to the endpoint's system time which the sensor relies on to assign timestamps to events/alerts. 
  • Most commonly occurs when system time changes backwards then forwards

Additional Notes

The backend tries to account for this with a "sensor drift" calculation. In cases with potentially large time discrepancies on the endpoint, this results in pushing events into the future.

Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎05-06-2022
Views:
100
Contributors