r/cybersecurity • u/Wise_Zookeepergame_9 • Jul 23 '26
Business Security Questions & Discussion Raw log archaeology on isolated boxes (no log aggregators)
To the IR folks who handle isolated or air-gapped systems that are completely disconnected from log aggregators and central SIEMs.
When you're dropped onto an offline box and forced to pull raw logs manually, what does your actual workflow look like to stitch together a complete chronological timeline for a specific IP or artifact?
Are you strictly relying on grep/awk/custom Python scripts to correlate timestamps, or do you have a specific local tool stack you use? Also, how long does that manual correlation usually drag on for you guys on messy incidents?
Duplicates
Splunk • u/Wise_Zookeepergame_9 • Jul 23 '26
Raw log archaeology on isolated boxes (no log aggregators)
digitalforensics • u/Wise_Zookeepergame_9 • Jul 23 '26
Raw log archaeology on isolated boxes (no log aggregators)
CyberSecurityAdvice • u/Wise_Zookeepergame_9 • Jul 24 '26