Timezone used by Azure Sentinel

VizPro1985 6 Reputation points
2021-01-19T17:28:08.26+00:00

What timezone is used by Azure sentinel? Below are what showing up in the Sentinel portal.

Last update time
01/02/21, 08:41 AM

Creation time
01/02/21, 08:41 AM

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} vote

3 answers

Sort by: Most helpful
  1. Clive Watson 7,866 Reputation points MVP Volunteer Moderator
    2022-09-12T16:59:46.45+00:00

    Sentinel uses UTC. You can toggle in the Logs blade UI to change this, but the change is temporary. One other choice is to alter the output of any Analytic or query to the local time https://learn.microsoft.com/en-us/azure/data-explorer/kusto/query/datetime-utc-to-local-function

    Please accept answer if this helps you

    1 person found this answer helpful.

  2. Manu Philip 20,456 Reputation points MVP Volunteer Moderator
    2021-01-19T17:50:08.237+00:00

    It is always good policy to manually set the time zone for all Event Source nodes in the Event Source Manager. Always remember to includes the time zone in the time stamp. This will help to understand the time easily


  3. JamesTran-MSFT 37,181 Reputation points Microsoft Employee Moderator
    2021-01-19T22:30:45.813+00:00

    @VizPro1985
    Thank you for your question!

    Based off what I found, it looks like Azure Sentinel goes off of UTC, if you're seeing inaccurate times or are having issues with Azure Sentinel, I'd recommend creating a support request so our engineers can take a closer look into your issue. Lastly, here are some other Azure Sentinel resources that you can leverage.

    58264-image.png

    If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.