Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

Could a device clock be wrong?

Yes. A device can consistently record the wrong time because its clock, time zone or automatic-time configuration is incorrect. Its timestamps remain evidence of what the device recorded, but not necessarily of the exact real-world time.

Several faults produce different patterns

A manually set clock may have a stable offset. Gradual movement suggests clock drift. A wrong time zone often creates an offset in whole hours, while a failed battery or long power loss can produce a much larger date error. Travel, disabled automatic time and failed network synchronisation can also matter.

Those causes are not interchangeable. A stable two-hour difference may support a bounded conversion; an offset that changes during the period does not.

Establish the error at the relevant time

Preserve the original timestamp, displayed zone and configuration. Time-service events, manual-change records, restarts and repeated comparisons with independently timed server activity may reveal when an error began or was corrected.

If the device is available, document its present time against a reliable reference without changing it. Treat that observation as current state only: later synchronisation, drift or user action may mean the same difference did not exist during the investigated event.

The point to remember

Identify the clock fault and its historical extent before converting device timestamps or using them to order events.

Reference: LOG-063Logs, Records & Provider Evidence