1. The Question
Did the logged session trigger the misfire counter DTC, or was it already stored?
After a diagnostic logging session, a scan showed a pending misfire-history code. The immediate assumption was that the test drive caused it. A freeze-frame review told a different story: the code's stored timestamp and operating-hours counter predated the session by weeks.
Fault codes carry no loyalty to when they were found. A code read after a session describes the state of memory, not the cause of it — yet post-test scans get treated as post-test evidence almost by reflex.
The real question was chronological: when did the misfire counter first increment? Freeze-frame data and the operating-hours counter answer that directly — but only if someone thinks to read them before assuming.
2. The Vehicle State
2018 compact crossover, 87,000 km. A full DTC scan including pending and history codes was not performed before the recording session began.
The pre-test state of the fault memory was, effectively, unknown until it mattered.
At 87,000 km, a history of stored and cleared codes is the rule, not the exception. Without a pre-session scan, every old entry in fault memory becomes a suspect for whatever the new session was testing.
A one-minute scan before recording — pending, stored, permanent, and history entries with their timestamps — turns the fault memory from a trap into a reference. It is step zero precisely because it cannot be done retroactively.
3. The Conditions
The session itself was a moderate-load road drive — nothing in the recorded channels approached conditions typically associated with misfire counting.
The drive looked innocent. The timing looked guilty. Only the stored history was objective.
The drive itself never approached the load region where misfire counting typically runs: moderate throttle, suburban speeds, no sustained high-load pull. Suspicion rested on sequence — 'we tested, then we found a code' — and sequence is the weakest form of evidence.
Documenting what the session did not do mattered here. The logged channels showed an ordinary drive, which is exactly the alibi the session needed once the timeline was checked.
4. The Recorded Window
The recorded window covered the drive cleanly. The diagnostic event in question was outside it by an order of magnitude in time.
The log could not acquit itself until the freeze-frame data was read.
The recording window was honest but narrow in time: it covered the drive, while the diagnostic event being blamed on it sat weeks in the past. No amount of zooming inside the file could touch an event outside it.
This is the mirror image of the missed-event case: here the 'event' was never going to be in the window at all. The window had to be extended backwards in a different way — through stored vehicle memory, not more recording.
5. The Observation
Freeze-frame operating-hours and the history counter placed the code's first registration well before the test date. The session did not produce the code — it merely revealed that nobody had looked.
Checking DTC context before logging would have documented this in one line.
Freeze-frame hours placed first registration roughly three weeks before the test date, under a highway load profile nothing like the logged commute. The session was cleared by the vehicle's own bookkeeping — evidence that existed the whole time, unread.
The lesson generalises: a finding's timestamp is part of the finding. Reading 'a code exists' as 'the test caused a code' skips the one field that separates correlation from sequence.
6. The Follow-Up Question
Make 'scan and record existing DTC context' step zero of every session — including pending, permanent, and history codes with their stored timestamps.
Every later finding then stands on a documented starting point.
The updated session checklist now opens with fault-memory capture: screenshot or record all DTC categories before the wheels move, then again after. New entries between the two scans are the session's to explain; older ones are background.
One line of pre-test documentation would have ended this case in a minute. The vehicle already knew the answer — the procedure just had to ask it in the right order.
What was happening when this data was recorded? If the sheet cannot answer that, the log is not evidence yet — it is just a file.— Lisa Moreno, LogContext Journal
Comments & Verification Notes
No peer comments recorded yet. Be the first to submit a technical note.