What should be recorded about each timeline entry?¶
Record enough to locate the source, understand what the system observed and reproduce any timing or interpretive work. A copied timestamp and narrative label are insufficient.
Preserve identity and timing fields¶
Include source system and dataset, evidence reference, event or record ID, original timestamp and zone, event stage and any converted value with its method. Add relevant account, device, session, address, process, object, result and correlation identifiers.
State whether the entry is raw, exported, parsed, enriched, alerted or assessed. Record filters and selection criteria where it was chosen from a larger dataset.
Write observations before conclusions¶
Describe what the system recorded - for example, that an account authenticated - rather than embedding unsupported personal attribution. Note uncertainty about clock, field meaning, identity or outcome and distinguish analyst annotations from source text.
The preserved source pointer lets another reviewer verify the entry if displays, metadata or memory later change. Traceability is what turns a table row into a reviewable evidential timeline.
The point to remember
Each timeline row needs source, identifiers, original time, event meaning, processing state and uncertainty.