Despite the widespread use of computing in almost all functions of contemporary society and the consequently large number of forensic investigations where computing has been involved, there has been little progress made in adapting the primary mechanism by which computers record past activity, namely event logs to facilitate computer forensic investigation. From an evidence point of view system event logs do not readily conform to the requirements of a forensic investigation. We identify two criteria
A. Ahmad, Anthonie B. Ruighaver