What is the overall investigator checklist for logs, events, alerts and timelines?¶
Use the checklist to preserve the evidence path from source record to reported conclusion. It keeps technical observations, analytic products and personal attribution from being collapsed together.
Establish the evidence before interpreting it¶
- Identify the creating system and whether the material is native, exported, parsed, enriched or correlated.
- Obtain field and result definitions, event stage, original time, zone and precision.
- Record accounts, devices, sessions, applications, processes, addresses and strong link identifiers without treating any as a person.
- Consider human input, automation, service identities, remote control, administrator action and compromised sessions.
- Test historical logging, retention, filters, collection health, overwrite and alternative copies; preserve volatile records early.
Keep analysis reproducible and proportionate¶
For alerts, retain the rule, version, logic, inputs, severity basis and analyst history, then examine source events. For timelines, preserve original times, document conversions and links, and show gaps, contradictions and uncertain order.
Report what each system recorded, the evidence supporting attribution, realistic alternatives and remaining uncertainty. Stop when additional work is unlikely to change the material decision, and record why.
The point to remember
A defensible log investigation preserves source, meaning, time, identity, automation, completeness, analytic logic and reporting limits.