Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

Does matching time prove that two records relate to the same event?

No. Time is a correlation clue, not a unique identifier. Busy systems can record unrelated activity in the same second, and timestamp precision or clock error can make related events look equal or reversed.

Displayed times may not describe the same stage

One value may be rounded while another is truncated. A client can record request creation, a server receipt and a SIEM ingestion. Time-zone conversion, buffering and drift add further difference.

The permitted correlation window should reflect the process and known clock quality; a fixed five-second window is neither universally narrow nor universally safe.

Seek identifiers and a plausible sequence

Combine time with account, device, addresses, session, request, message or transaction IDs and hashes. Confirm that the expected workflow makes sense - for example, request before response after accounting for supported clock offset.

Where time is the only match, describe the records as potentially related. Stronger identity between them requires additional compatible source fields or specialist interpretation.

The point to remember

Matching timestamps support a possible link only when precision, clocks, event stages and other identifiers also fit.

Reference: LOG-134Logs, Records & Provider Evidence