Why should an authentication log be copied to a working location before incident analysis?
The existence of any copied file proves which IP performed an attack.
Copying automatically erases the original log to hide sensitive data.
The copy rewrites all event timestamps into the current time.
It lets investigators work on a duplicate while leaving the original evidence unchanged.