For event logs to be acceptable for incident investigation, which of the following is the MOST important consideration to establish chain of evidence?
Centralized logging
Time clock synchronization
Available forensic tools
Administrator log access
Submit