Skip to content
LOG-000 Logs, Records & Provider Evidence

A log, event or alert may be relevant to my investigation — where do I start?

You have been given a log extract, an alert, a dashboard screenshot or an event report. Before interpreting it, establish exactly what you have.

Avoid this assumption: That every technical-looking record is direct evidence of what a person did. It may instead be a system-generated entry, an automated detection, a normalised dashboard record or an analyst’s interpretation of underlying data. Start with five questions.

What system created the record?

What activity was that system configured to record?

Is this the original source record, an export, a screenshot, a report or an alert generated from other events?

What do the fields mean?

What surrounding records are available?

Do not begin with attribution. First identify the source, event type, timestamp basis, account or device identifiers, status fields and any event code. A username, hostname or IP address may help link activity, but it does not automatically identify the human responsible.

Preserve the material in the form supplied. Where possible, request the original export, field definitions, time-zone information, the relevant retention period and records before and after the event. If an alert is involved, ask for the detection rule, the rule version, the source events and any analyst notes.

Consider whether the activity could have been generated automatically by a service, scheduled task, API, security tool, synchronisation process or compromised session. Also check whether missing records could result from filtering, retention, collection failure or logging settings.

Then define the investigative question. Are you trying to establish that an event occurred, that an account was used, that a device communicated, that a control was bypassed, or that a particular person was responsible? Different questions require different corroboration.

Specialist support may be needed where event definitions are unclear, several systems disagree, the records are incomplete or attribution will carry significant evidential weight.

Operational takeaway

Identify the source, preserve the underlying records and define the investigative question before drawing any conclusion from a log, event or alert.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.