Analyzing data
Analyzing Hadoop data in a forensic investigation, also known as forensic analytics, is the process of running tests against the data to isolate events, trends, and patterns that relate to the investigation. Investigators have a large set of techniques for performing the analysis that meets the needs of the case. Each investigation is different, and each requires its own type of analysis. In some cases, not much is known about how the data relates to the facts of the investigation. In other cases, a single data point that represents an event or fact is believed to reside in the data. The role of the investigator is to understand the data and run an analysis that brings out the facts of the case in a clear, understandable way.
Investigators should begin the analysis with an approach and plan in place. The investigation began with a set of issues and facts that need to be proven or further developed. In addition, the preceding steps of the process, such as interviews and documentation...