The various components within the network infrastructure providing the log records must have their clocks synchronized using a common time reference so the events can be correlated in exact order of time. Without synchronized time, accurately correlating information between devices becomes difficult, if not impossible. If sensor logs cannot be correlated with the routers, switches, and firewalls, it may not be possible to trace all the damage caused by a network breach. NTP provides an efficient and scalable method for network elements to synchronize to an accurate time source. |