Skip to content
Skip to main content
Logs, Records & Provider Evidence Operational Explainer

How should contradictory logs be handled?

Preserve and define the contradiction before trying to resolve it. Different results can reflect separate stages or observation points rather than false or manipulated records.

Identify exactly what conflicts

A client may record “sent” while a server rejects receipt, or a firewall may allow transport before an application denies access. UTC conversion, delayed ingestion, parser errors, stale identity data and incomplete exports can create apparent differences in time, actor or result.

First verify that records concern the same event using session, request, transaction or correlation identifiers - not merely a matching username and approximate time.

Weigh each source at its observation point

Obtain native records and field definitions and ask which system directly observed the disputed fact. The server may best evidence receipt; the client may uniquely show local initiation. Record possible resolutions and further evidence needed.

If the conflict remains, show it in the timeline or report. Selecting the preferred entry would conceal a limitation that may itself be significant.

The point to remember

Contradictory logs require event identity, stage and source analysis; unresolved differences must remain visible.

Reference: LOG-139Logs, Records & Provider Evidence