The challenge
Three synthetic log entries arrive out of order. Build a timeline while preserving the original line numbers so each conclusion can be traced back to its source.
Normalize without discarding
from datetime import datetime
lines = [
"2026-09-01T10:02:00+00:00 request-complete",
"2026-09-01T10:00:00+00:00 session-start",
"2026-09-01T10:01:00+00:00 request-start",
]
records = []
for number, line in enumerate(lines, start=1):
timestamp, event = line.split(" ", 1)
records.append((datetime.fromisoformat(timestamp), number, event))
for timestamp, number, event in sorted(records):
print(timestamp.isoformat(), number, event)
Keep uncertainty visible
Sorting timestamps does not prove causal order across multiple machines. Clock drift, buffering and differing time zones can all change the interpretation.
Preserve raw evidence. Treat normalization as a derived view.
Lessons learned
Record timezone assumptions, parser versions and source identifiers. Reproducibility matters more than a clean-looking timeline.