How should logs from several systems be compared?¶
Understand each source first, then align its observation point, fields, time and identifiers with the others. Identical labels across products should not be assumed to have identical meanings.
Normalise without discarding source meaning¶
One “user” field may be an authenticated account and another a process owner. “Success” may mean request accepted, connection allowed or transaction completed. Record source, event type, definitions, original timestamp and zone, event stage and retention before converting or mapping anything.
A comparison table can keep original time, converted time, actor, device, address, action, result and link identifiers visible, marking absent and inferred fields explicitly.
Resolve relationships rather than smoothing differences¶
Prefer request, session, message and transaction IDs over timing alone. Check whether one system imports another. Apparent contradictions may reveal different stages, clock faults, retries or incomplete collection and should remain visible.
Record conversion and interpretation methods so another reviewer can reproduce the comparison and distinguish source fact from analytical mapping.
The point to remember
Compare multi-system logs through source-specific definitions and explicit mappings, while preserving original values and contradictions.