Log analysis
Converts a vague question about whether something happened into a scoped search with a written answer, its sources, and its limits.
Tools
Splunk, Microsoft Sentinel, Graylog, Elastic Security
Outcomes
Every question answered from a logged search • Searches recorded with sources and time range • Retention gaps named before they hide a result • One shared timeline per investigation
Documentation
Instruction-ready detail below
An investigation usually arrives as a question rather than a dataset, and the real work is working out which log source holds the answer, how far back it reaches, and what a negative result would look like. This workflow takes the question as written, names the systems and accounts involved, and turns it into a scoped search with an explicit time range and list of sources, so the scope is agreed before anyone starts reading. It runs the search across the collected sources, adds the context a raw result needs to be read, such as which users sit in an admin group, and writes every query and source into the case as it goes. If a source the question depends on has no data covering the period, the answer says so rather than returning a clean empty result. The finding is written as a short summary with its confidence and its limits, attached to one timeline other responders can pick up. A human still decides whether an absence of evidence is acceptable, and who else should see the answer.