Skip to content

Improve log analysis timestamp and entity normalization guidance#1165

Open
KooZuKi wants to merge 1 commit into
UnitOneAI:mainfrom
KooZuKi:improve/log-analysis-normalization-evidence
Open

Improve log analysis timestamp and entity normalization guidance#1165
KooZuKi wants to merge 1 commit into
UnitOneAI:mainfrom
KooZuKi:improve/log-analysis-normalization-evidence

Conversation

@KooZuKi
Copy link
Copy Markdown

@KooZuKi KooZuKi commented Jun 5, 2026

Summary

  • Add timestamp provenance preflight guidance for event time, device time, collector time, ingestion time, and normalized time.
  • Add entity-normalization evidence for cross-source user, host, device, IP, and cloud-principal pivots.
  • Extend the output template with source quality, ingestion lag, clock-skew, parser/schema, and join-confidence fields.
  • Add severity and pitfall guidance for ingestion-order timelines, raw local timestamps, and ambiguous entity joins.

Validation

  • git diff --check
  • Local frontmatter check using the repository workflow required fields
  • Local prompt-injection scan using the repository workflow patterns

Closes #1142

Bounty

Improver contribution. Preferred payment method can be provided privately after acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] log-analysis: add timestamp and entity normalization evidence

1 participant