Machine records,
read to the second.
Logs are written by systems, not people, which is what makes them useful. The handler reads them line by line with timestamps as fields, so an event can be placed at a second rather than a day.
LLX-HANDLER-LOG · R2 · 4 formats
Three things a grep through a log file loses.
Timestamps as fields
A time is read as a time, in its own timezone, so lines from different systems can be put on one axis.
Line identity
Each line keeps its position and its file, so an event is citable rather than merely findable.
Configuration state
Settings files are read as key and value, which is how you show what a system was set to do.
The questions machine records usually decide.
When something actually happened
An event is cited to its line and its second, independent of anyone’s account of it.
ChronologyWho overrode a control
An override or manual action is read with the identifier the system recorded against it.
AttributionHow a system was configured
A configuration is read as values at a date, so behaviour can be explained rather than inferred.
ConfigurationRead in place, in the format it arrived in.
The file is never converted or re-saved. It is read where it lies, and the handler records a SHA-512 of the bytes it read — so a passage cited today can be replayed against the same file years from now.