> or should it be read as "the system logs don't have the year"?
That's the case. RFC 3164, which specifies the log format, is the only one usbrip can read, and it doesn't have an option to specify year.
Well, then the tool has no actual "forensics" use by itself.
It's a pity, of course, but it can only be a tool to confirm findings that have a "proper" timestamp.
Most probably the log consists of "appended" entries that might mitigate the issue, still it is needed a clear and extended "justification" to the procedure with wich the year is "attributed" to the yearless entry for forensics use.