SiliciumHex FieldKit

Problem Solving & Quality · Observe

Event Timeline Reconstruction

Rebuild minute by minute what happened before the failure from logs, historian data, shift notes and witnesses — and mark every gap.

  • Time45 min
  • FormatSmall group
  • StageObserve

Event Timeline Reconstruction: what it is and why it works

Event timeline reconstruction rebuilds, minute by minute, what happened before a failure, spill, trip or quality escape. It starts from an anchor, the exact time of failure or detection, and gathers every time-stamped source: control-system historian data, alarm and event lists, shift logs, work orders, access records and witness accounts. All clocks are aligned to one reference, events are placed on a single line going back until conditions were normal, and every gap and contradiction is marked as a question for the cause analysis.

Contradictory accounts are normal after an incident. People remember in fragments and often out of order, and each system keeps its own clock. A single reconciled timeline replaces argument with sequence: it shows which event came first, how long conditions were abnormal and what operators could have seen at each point. It is especially valuable for trips, upsets and accidents, where timing drives causality. It depends on evidence preservation, because overwritten logs cannot be recovered, and it feeds both change analysis, by showing what changed just before the event, and fault tree analysis, by showing which basic events actually occurred and in what order.

What you need

  • The anchor time of the failure or detection
  • Historian trends and alarm and event lists exported for the relevant window
  • Shift logs, work orders, permits and access records
  • Witness accounts collected early and separately
  • Known or measurable clock offsets between systems

What you get

  • A single reconciled timeline with a source for every entry
  • A record of the clock corrections applied
  • Witness accounts placed on the line and distinguished from recorded data
  • A list of gaps and contradictions
  • Questions to test in the root-cause analysis

When to use it

After a breakdown, a spill or a trip, when accounts contradict each other.

How to do it, step by step

  1. Fix the anchor: the exact time of the failure or detection.
  2. Gather time-stamped sources: control-system historian, alarm and event lists, shift logs, work orders, access records.
  3. Align all clocks to one reference; note the offsets you corrected.
  4. Place every event on one line, going back until conditions were normal; add witness accounts in a different color.
  5. Mark gaps and contradictions, then list the questions they raise for the cause analysis.

Worked example: Refrigeration compressor trip at a cold-storage warehouse

Illustrative scenario — figures are realistic but not from a real company.

A refrigeration compressor at a frozen-food distribution center trips on high discharge pressure at night, and a 40,000-sq-ft freezer starts warming toward its alarm limit. The night technician says a condenser fan failed first; the controls contractor insists the compressor tripped before any fan alarm.

  1. Anchor: the compressor trip recorded by the compressor controller at 01:47:10.
  2. Sources: the compressor controller event log, building management system (BMS) trends for condenser fans and pressures, the technician's log and machine-room badge records.
  3. Clock check: using a manual compressor start recorded by both systems the day before, the BMS clock was found 2 min 40 s ahead of the compressor controller. After correction, the fan 3 overload came 1 min 55 s before the trip, not after it.
  4. The line was built back to 23:30, when pressures were normal. Witness entries, in another color, showed the technician passed the condenser at 00:50 and noticed nothing unusual.
  5. Gap: the condenser spray pump's status was not logged, so there was no direct record of it. The condensing-pressure trend began rising around 01:20, which became a question for the investigation.

Result. The reconciled sequence showed the spray pump most likely stopped around 01:20, fan 3 then tripped on overload, and discharge pressure climbed until the compressor's safety trip acted as designed. Both accounts were partly right. The team replaced a faulty pump control relay and added the pump status to the historian. A standby compressor kept the freezer within limits.

Common pitfalls and how to avoid them

  • Trusting raw timestamps from different systems.Measure clock offsets against an event recorded by several systems and correct them before ordering events.
  • Starting too close to the failure.Go back until conditions were clearly normal; slow drifts often start hours or days earlier.
  • Mixing witness memory with recorded data.Show witness accounts in a different color and treat their times as estimates.
  • Filling gaps with guesses.Mark gaps explicitly and turn them into questions or data requests.

Frequently asked questions

How do you build a timeline for an incident investigation?

Fix the anchor time, collect every time-stamped source, align all clocks to one reference, and place events on a single line going back to normal conditions. Add witness accounts separately and mark their times as estimates. Note every gap and contradiction, and keep the source of each entry so that anyone reviewing the timeline can check it.

Why do clock offsets matter in event reconstruction?

Control systems, PLCs, cameras and access systems often run on unsynchronized clocks that drift by seconds or minutes. In a fast sequence, even a small offset can make an effect appear before its cause. Correcting offsets, using an event recorded by several systems as the reference, is essential before drawing any conclusion about the order of events.

When should witness interviews be done?

As soon as practical after the event, once people are safe, because memory fades and accounts tend to converge once people talk to each other. Interview witnesses separately, ask them to describe what they saw and heard in their own words, and avoid showing them the timeline first so their account is not shaped by it.

Origin

Sequence-of-events reconstruction — standard incident and accident investigation practice; no single author.

Used in these playbooks

Major breakdown investigation 1 week

One week after a trip, a leak or a critical equipment failure: rebuild the sequence, map the failure combinations, dig to the cause, choose strong barriers and record the lesson.

  1. Event Timeline Reconstruction
  2. Fault Tree Analysis
  3. 5 Whys
  4. Hierarchy of Controls
  5. Lessons Learned Register

Related methods

More in “Observe”

Go where the problem happens and collect facts, counts and timelines — not opinions.