Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What can a single log entry actually prove?

Usually, it proves that a named system recorded a defined event or condition in a particular form. Its fields may support time, account, endpoint, session, address, event code and status - but not the whole sequence or human attribution.

Meaning depends on source conditions

Logging configuration, field definitions, clock, provenance and later filtering or enrichment affect the row. A success may mean request acceptance rather than completed outcome; a failure may be followed by success elsewhere. Scripts, services and scheduled tasks can use human-looking accounts.

Extend outward from the entry

Preserve the original row, surrounding period and linked request, session and correlation IDs. Compare other source systems, endpoints, physical access, communications and witness evidence.

State exactly what this system observed, then identify separately what corroborates event sequence, operator and purpose.

The point to remember

Use one log entry for the narrow system fact it supports and corroborate sequence and attribution independently.

Reference: LOG-006Logs, Records & Provider Evidence