MYTHOSAI

Incident recovery / PRACTICAL GUIDE

Preserve security logs before routine cleanup

Keep a reproducible evidence copy with its collection context and access controls.

Before you start

Authorised access to the relevant logs and an approved private storage location.

Preserve context as well as files

A log export is useful only when another authorised person can understand where it came from and what period it covers. The same timestamp can mean different things across systems using UTC, local time or an incorrect clock. Logs can also contain usernames, addresses and application data that should not be published.

Use the product's supported export function. This guide does not replace a formal forensic process or authorise collecting unrelated personal data from systems outside your responsibility.

Collect a defined range

  1. Identify the log source, host, product version and relevant time range. Note the system's time zone and any known clock discrepancy before comparing events.
  2. Export the original structured format where the product supports it. A screenshot can supplement an export, but it may omit fields or make searching difficult.
  3. Save the export in the approved incident folder with a clear filename and collection time. Preserve the source settings and retention information without copying passwords or secret configuration unnecessarily.
  4. Restrict access to the incident team and make a protected backup according to the response process. Document who collected the file and any later transformation performed for analysis.

Verify the copy

Open the exported copy using a supported reader and confirm it contains the intended range. Where appropriate, calculate a hash to recognise whether that particular copy changes later. A matching hash establishes byte consistency; it does not prove that the source logs are complete or that the originating system was trustworthy.

Keep original and analysis separate

Use a working copy for filtering, annotation and conversion. Label a sanitised extract as an extract. Do not overwrite the original export with a spreadsheet that drops fields or changes timestamp formats.

Avoid premature cleanup

Routine log deletion, retention changes or reinstalling a service can remove evidence. Coordinate those actions with the incident owner while keeping essential services operational. If storage pressure requires action, document the tradeoff and preserve the relevant range first where possible.

Share the minimum needed

Send evidence only through the approved support route, with access and retention appropriate to its contents. Public forum posts should use small sanitised samples. Good collection helps a responder reproduce an observation, while clear limits prevent a partial log from being mistaken for a complete account of the incident.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.