What should be recorded about each timeline entry?¶
Each timeline entry should contain enough information for another investigator to understand, locate and assess the underlying record.
A timestamp and short description are not enough.
Avoid the dangerous assumption¶
The dangerous assumption is that the source details can be reconstructed later if the event becomes important.
They may be lost, changed or forgotten.
Record the source system, log name or dataset, event ID or record identifier, original timestamp, time zone and any converted time. Distinguish event time from ingestion or processing time.
Record the account, device, session, address, process, object and result where relevant. Include request, correlation, transaction or message identifiers that link the event to other records.
The description should state what the system recorded, not an unsupported conclusion. “Account X successfully authenticated” is safer than “the suspect logged in” unless attribution has been separately established.
Note whether the entry is a raw source event, export, dashboard representation, alert or analyst assessment. Record any filtering, parsing, normalisation or enrichment that affected it.
Where timing, identity or outcome is uncertain, include that limitation. If the entry has been converted from UTC to local time, preserve both values and the conversion basis.
The timeline should also point to the preserved source file or evidence reference. This allows review without relying on copied text alone.
Where an entry was selected from a larger dataset, record the search or selection basis so its inclusion can be reviewed and reproduced.
Operational takeaway¶
Every timeline entry should preserve source, identifiers, original time, event meaning, result, processing status and uncertainty so the record remains traceable, reviewable and resistant to overstatement.