QRadar system time

When your deployment spans multiple time zones, configure all appliances to use the same time zone as the IBM QRadar Console. Alternatively, you can configure all appliances to use Coordinated Universal Time (UTC).

Configure the IBM QRadar system time from the QRadar user interface. You can configure the time manually, or by configuring Network Time Protocol (NTP) servers to maintain the system time.

You cannot sync external device clocks to IBM QRadar on Cloud. QRadar on Cloud doesn't use a public NTP system to sync. Instead, it syncs by using the IBM Cloud GPS-based time service.

The time is automatically synchronized between the QRadar Console and the managed hosts.

Problems that are caused by mismatched time zones

To ensure that searches and data-related functions work properly, all appliances must synchronize time settings with the QRadar Console appliance. When the time zone settings are mismatched, you might see inconsistent results between QRadar searches and report data.

The Accumulator service runs on all appliances with local storage to create minute by minute accumulations, and hourly and daily roll ups. QRadar uses the accumulated data in reports and time series graphs. When the time zones are mismatched in a distributed deployment, report and time series graphs might show inconsistent results when compared to AQL query results due to the way that the accumulated data is aggregated.

QRadar searches run against data that is stored in the Ariel databases, which use a date structure (YYYY/MM/DD/HH/MM) to store files to disk. Changing the time zone after the data is written to disk disrupts the file naming sequence in the Ariel databases and might cause data integrity problems.