Skip to content
Skip to main content
Logs, Records & Provider Evidence Investigation walkthrough

I have been given a log, event or provider return. What happens next?

Nadia Holt reports that Owen Kerr repeatedly appeared near private repair appointments and later messaged details held only in her housing-provider account. The provider supplies a spreadsheet of audit events showing contractor account CTR-2041 viewing her restricted tenant record. This walkthrough turns those rows into an evidential timeline and tests whether the account activity leads to Owen as a stalking suspect.

The working principle
Understand each source before joining the rows. A log entry is one system's record of an event. Preserve its provenance, field meanings, time basis and completeness; then correlate it with other records using identifiers that genuinely belong together.
Victim's account
Audit export
Field meanings
Authentication session
Independent access records
Device evidence
Suspect

A username, workstation or successful login does not identify a human on its own. Repeated agreement between audit, authentication, physical-access, communication and device records can nevertheless provide a strong circumstantial case.

The material received

What the housing provider supplies
Workbookrestricted-record-review.xlsx, produced by the provider's security team.
Target recordTenant TEN-50882, belonging to Nadia Holt.
AccountContractor account CTR-2041, issued to Owen Kerr.
Reported patternFourteen record views and three document exports across six dates.

The workbook is useful, but it is a presentation created from several systems. It may sort, rename or omit fields. The difference between an event and a log entry matters here: Nadia's record was viewed; the audit entry is the housing system's representation of that view; and the spreadsheet is a further export of that representation.

One row from the supplied workbook
event_time=2026-06-03T08:13:09Zevent_type=VIEW_RESTRICTED_RECORDactor_account=CTR-2041target_id=TEN-50882session_id=SES-A74Cworkstation_id=WS-17
Established the workbook presents this account, target, session and time togetherStill open the row's provenance, precise field meanings and the person using the account
EstablishedThe provider has identified a repeated pattern of restricted-record access associated with account CTR-2041.
Still openWhether the export is complete and accurate, what each event means, and whether Owen personally caused the relevant activity.

Work the records into an evidential timeline

01 · Identify the producing systems and original records

The workbook combines housing audit data, authentication events and door-access records; it is not the original record from any of them.

Record who produced the workbook, from which systems, using what filters and at what time. A log export may omit events or fields, so retain the original exports and their metadata where available. Preserving the source records allows later interpretation to be checked rather than treating a helpful spreadsheet as an unexplained oracle.

Investigator action
Obtain the original exports, provider explanation, field definitions, query or filtering method, time-zone information and continuity record. Keep the analyst workbook as an index rather than silently promoting it to the source.

02 · Establish what the fields and times mean

The housing system distinguishes the event time from the later ingestion time and uses a stable tenant identifier rather than Nadia's displayed name.

VIEW_RESTRICTED_RECORD means the application returned Nadia's restricted record to an authenticated session. It does not prove every field was read or remembered. EXPORT_APPOINTMENT means the system generated a document; a separate download event addresses whether it left the application.

Event time2026-06-03T08:13:09.441ZWhen the housing application says the view occurred.
Ingestion time2026-06-03T08:13:14.806ZWhen the central logging service received the entry.

Event time and ingestion time answer different questions. The trailing Z indicates UTC; time-zone interpretation becomes essential when comparing this entry with local door access, messages or witness accounts.

03 · Follow stable identifiers across the sequence

Session SES-A74C authenticates, views Nadia's record and exports her repair appointment within three minutes.

08:12:44Authentication service accepts account CTR-2041 on workstation WS-17; session SES-A74C begins.
08:13:09Housing audit records VIEW_RESTRICTED_RECORD for TEN-50882.
08:14:18The session creates appointment export REP-7714.
08:15:02Download service records REP-7714 delivered to workstation WS-17.

Stable account, tenant, session, report and workstation identifiers create a defensible relationship between the events. Mere proximity in a spreadsheet would be weaker. A successful login establishes acceptance of the authentication, not the identity of the operator; that is the next proposition.

04 · Compare genuinely independent records

Owen's issued access badge enters the contractor office four minutes before session SES-A74C; Nadia receives a message quoting the appointment 19 minutes after the export.

Independent records around 3 June
Door system08:08:51 · BADGE-119badge issued to Owen Kerr enters contractor office
Housing system08:12-08:15 · SES-A74CNadia's record viewed and appointment REP-7714 downloaded
Victim's message08:34:27sender quotes the private repair time and street
Different systems record access, application activity and communication

The badge identifies an issued credential, not necessarily the person carrying it. The message identifies an account, not automatically its author. Their value comes from independent agreement on a distinctive sequence repeated across several dates. Owen's work rota and workstation assignment add further support; unrelated staff use does not appear in the relevant sessions.

05 · Test the logged activity against device evidence and conduct

A phone recovered from Owen contains Nadia's appointment export REP-7714, screenshots of her restricted record and messages sent shortly after the recorded views.

The report identifier and file hash match the provider download. The phone also contains the account used for the messages and photographs taken near two appointment locations. None of those facts needs the log row to prove its own existence; together they strongly corroborate that the housing access was used as part of the reported stalking conduct.

This combination moves well beyond “Owen had an account”. Repeated relevant-time badge access, one workstation and session, targeted record views, matching downloaded material and closely timed communications all point towards Owen. An IP address in a log would not identify him, and neither does a username. Attributing authentication events to a person is built through the wider agreement.

EstablishedIndependent system, physical-access, message and device evidence converges on Owen-associated access to Nadia's restricted information across the reported dates.
Still openOwen's explanation, access to his badge and devices, the purpose of each view, and whether any other person participated.

Where this leaves the investigation

Source recordsOriginal audit, authentication and door exports preserve the provenance behind the analyst workbook.
Repeated sequenceStable identifiers join targeted views and exports across six dates.
Primary suspectBadge, rota, workstation, communications and recovered-device evidence provide a strong route to Owen Kerr.
Further line of enquiryTest Owen's account and place the logged access within the full pattern of stalking conduct reported by Nadia.
Operational takeaway
Good correlation preserves the differences between sources. Understand the record, align time carefully and look positively for independent agreement on distinctive identifiers and conduct. That is how a spreadsheet becomes a strong evidential timeline rather than a colourful collection of rows.
Reference: LOG-000Logs, Records & Provider Evidence