Skip to content

Glossary

ZSECONDSFROMGMT

ZSECONDSFROMGMT is the knowledgeC.db column with the device UTC offset in seconds. Local time = UTC + offset; changes hint at travel or time zone edits.

ZSECONDSFROMGMT is a ZOBJECT column holding the device's offset from UTC, in seconds, at the time of the event. The dates in knowledgeC.db are stored in UTC, so local time is UTC plus this offset: a value of 7200 means the Mac was on UTC+2, and -18000 means UTC-5.

SELECT datetime(ZSTARTDATE + ZSECONDSFROMGMT + 978307200, 'unixepoch') AS start_local
FROM ZOBJECT;

The column serves two purposes. It shows the time the user saw on screen, which matters when a witness says "around 3 a.m.". And a change in the value between events indicates travel or a time zone change on the device. Report UTC, and give local time together with the offset you applied. See Mac absolute time and who was at the keyboard.