pfsense 2.6.0 Time‑Zone Setting: Resolving Log Timestamp Ambiguity During DST Transitions
26.5K reputation · 28 Jun 2025, 19:46 UTC
Background
In pfSense 2.6.0 the global time‑zone setting under System > General Setup drives the OS clock and all local timestamps in the web interface and syslog. The NTP client synchronizes the clock, but the zone is applied only after boot; during an NTP adjustment logs may temporarily show UTC‑like timestamps until the zone is reloaded.
Current Ambiguity
When logs are forwarded to an external syslog server, pfSense transmits RFC 5424 timestamps with a local zone offset. RFC 5424 does not enforce a strict offset field, which can lead to ambiguity during daylight‑saving transitions. Documentation states that pfSense does not automatically adjust log timestamps for DST changes, and administrators must manually verify offsets when reviewing older logs.
Unresolved Decision
There is no official patch or documented feature request addressing potential misalignment of log timestamps during DST changes, leaving this behavior unresolved.
Questions
- In pfSense 2.6.0, does the NTP client re‑apply the configured time‑zone after each synchronization, or is the zone only set at boot?
- When forwarding logs to an RFC 5424‑compliant syslog server, how is the local offset represented, and does the server reliably interpret it during DST transitions?
- What configuration or workaround can guarantee that log timestamps remain consistent across DST changes without manual offset verification?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 29 Jun 2025, 07:22 UTC
While switching to UTC via System > Advanced > Miscellaneous resolves the DST offset ambiguity, it is important to note that log monotonicity still depends on the stability of the NTP synchronization. If the NTP client corrects a significant clock drift—rather than performing a gradual slew—you may still see jumps or gaps in the timestamps of forwarded logs.
To verify that your logs are remaining consistent across transitions, you can run the following commands via the pfSense shell to compare the local system time against the universal coordinate:
date
date -u
If you observe unexpected jumps in /var/log/system.log despite using UTC, check the NTP status to ensure the system is not frequently re-syncing due to an unstable upstream source, as this can introduce timing anomalies that UTC alone cannot fix.