Skip to content
Skip to main content
Logs, Records & Provider Evidence Operational Explainer

How should a log entry be described in an investigative report?

State what the identified system recorded, including source, event type, material fields, timestamp stage and result. Keep any inference about a person, intent or real-world outcome separate.

Technical labels need source definitions

An identity platform may record successful authentication for an account from an address; that is not automatically proof that the account holder logged in. Terms such as user, device, location and success should carry only the product-defined meaning.

Say whether the record is native, exported, normalised, enriched or displayed through a SIEM, and whether its time is source, converted or ingestion time.

Make every statement traceable

Include event or evidence reference and relevant session, request or transaction identifiers. Explain how it links to other records rather than relying on approximate time. Preserve original wording and identify specialist interpretation where used.

The report can then move from direct observation to a proportionate inference, showing the corroboration and limitations instead of embedding attribution inside the log description.

The point to remember

Describe the system observation first, then make any human or outcome inference explicit and supported.

Reference: LOG-147Logs, Records & Provider Evidence