> Source: [sk179433](https://support.checkpoint.com/results/sk/sk179433)

# sk179433 - Session logs show an inaccurate timestamp

| Property | Value |
|----------|-------|
| Solution ID | sk179433 |
| Date Created | 2022-06-01 |
| Last Modified | 2022-06-02 |
| Technical Level | Advanced |
| Products | Logging & Status |
| Versions | R82.10, R82.20, R81.20, R82 |
| OS | Gaia |

## Symptoms

- * Session logs show a timestamp for a session several hours after the session was closed.
* Session logs show user activity after users logged out.

## Cause

A session shows that a user is connected to a site or uses an application. A session starts when a user connects to a site or to an application. The Security Gateway includes all of the user's activity in the session in one session log.  

The session stays open while updates are sent and maintained with a "keep-alive" mechanism. By default, the Security Gateway closes the session after three hours if it does not receive updates.   

If there is a log switch while the session is open, the Log Server cannot unify previous session logs. This causes the Log Server to produce an inaccurate timestamp.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
