Skip to content
LOG-057 Logs, Records & Provider Evidence

Which clock created the timestamp?

Before relying on a timestamp, investigators should establish which clock created it.

The relevant clock might belong to a user device, server, cloud platform, network appliance, application, collector or SIEM.

Avoid this assumption: That every timestamp in a set of logs comes from the same accurate clock. It may not.

A laptop may record one time using its local system clock. A cloud service may record another using UTC. A collector may add a receipt time from its own server, and a dashboard may then convert that value again for display.

These different clocks can all produce legitimate timestamps for the same activity, but they describe different systems and sometimes different stages.

The clock source matters because devices can drift, be manually altered or lose time synchronisation. Virtual machines and embedded devices may behave differently from well-managed servers. Some systems rely on a central time service, while others use their own local settings.

Investigators should identify the field and originating component for every time central to the case. Ask whether the timestamp was generated at source or added later during collection, ingestion or display.

Obtain relevant configuration where proportionate, including time-zone settings and synchronisation sources. Check whether the system reported clock errors, recent restarts or manual time changes.

Where several clocks are involved, avoid forcing all records into one sequence until the relationship between those clocks is understood. Record any offset or uncertainty used.

Operational takeaway

The evidential value of a timestamp depends on knowing which clock created it, because different devices and services may record the same activity using different clocks and processing stages.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.