You need to merge log lines from three services into one consistent, replayable sequence, and someone proposes attaching a Lamport clock to every event and sorting by it. Does that give you what you need, and what does the resulting order actually guarantee?
It gives you a real, useful guarantee — just a narrower one than "the true order things happened", because across machines there usually isn't such a thing. A Lamport clock is a per-process counter, incremented on every local event and on every send, and set to max(local, received) + 1 on every receive; the resulting property is that if event A actually happened-before event B (the same process did both, in order, or a message connects them), then L(A) < L(B), always. Sorting by that number, with a process id to break ties, gives a total order that never contradicts causality — which is exactly what a replayable audit log needs: a single, consistent sequence to apply events in. What it does not give is the converse: L(A) < L(B) does not mean A caused B. Two events that happened independently on different services, with no message connecting them, are concurrent — there's no true answer to "which came first" — and a Lamport clock still assigns them some order, arbitrarily, because a total order has to put every pair of events somewhere.