What is a cloud-log export?¶
A cloud-log export is a copy of selected cloud records produced from a provider or organisational system.
Evidential caution: that an export is automatically raw, complete and unchanged.
What this means¶
It may be supplied as CSV, JSON, spreadsheet, report, archive or another structured format.
Exports may apply filters, field mapping, date limits, time-zone conversion and user-interface formatting.
Long identifiers can be truncated by spreadsheets. Timestamps can be reformatted. Some nested technical fields may be omitted.
Where structured data contains nested fields, preserve the original machine-readable form. Flattening it into a spreadsheet may separate values from the event or resource they belong to.
What to check or do next¶
- Investigators should record who created the export, from which system, when, using what permissions and with which filters.
- Preserve the original file before opening or converting it in software that may alter formatting.
- Check the field names, encoding, date range, row count and whether pagination or maximum-result limits applied.
- Where possible, obtain the provider’s schema or field definitions.
- Do not treat a screenshot or printed report as equivalent to a structured export if the underlying records are available.
- If the export was generated by a security platform rather than the provider, identify what processing, enrichment or normalisation occurred.
- Compare the export with the source interface or a second export where necessary to confirm scope.
- If the export was opened in spreadsheet software, verify that account IDs, IP addresses, timestamps and long technical values were not converted, rounded or displayed in scientific notation.
Operational takeaway
A cloud-log export is a generated representation of selected records, so preserve the original and document its source, filters, permissions and formatting limitations.