An administrator is troubleshooting a syslog integration where Secure Firewall Threat Defense is sending logs to a SIEM, but the receiving SIEM cannot parse the message headers properly because the timestamp format is in local time rather than UTC. Where can the timestamp format for syslog messages be adjusted on the FMC?
Syslog formatting options, including timestamps (UTC vs local), are configured within the Platform Settings policy applied to the FTD.
Why this answer
Syslog timestamp formats (such as UTC vs local time, and inclusion of year) are configured in the FTD Platform Settings under the Syslog or Time synchronization settings.