Should I ask for raw cloud logs or a provider summary?¶
Where possible, ask for the underlying cloud records rather than relying only on a provider summary.
A summary can be useful, but it may simplify, group or omit important fields.
What this means in practice¶
Those fields may allow events to be linked across several systems.
Investigators should ask what source records support the summary and whether the provider can preserve or supply them.
Where raw data is provided, preserve the original format and field definitions. Avoid reformatting before the source copy is secured.
Use the provider summary to explain the system, not to replace the technical records where those are available and proportionate.
Where the source record is technically complex, retain the provider’s explanatory material alongside it. Interpretation should remain tied to the original fields rather than replacing them with simplified wording.
What this may show¶
Raw or structured logs may include event IDs, session IDs, application IDs, resource identifiers, IP addresses, failure codes, correlation values and precise timestamps.
What this does not show on its own¶
The dangerous assumption is that a provider narrative contains the complete evidential picture.
A summary may still be necessary where the provider cannot disclose raw records, the system is complex or interpretation requires specialist explanation.
If the provider supplies only a summary, ask whether event-level records remain retained. A later lawful route may permit access even if the first response does not include them.
What to do next¶
Record who produced the summary, their role, the date, the systems consulted and any limitations.
Do not treat a spreadsheet export as automatically raw. It may be filtered, normalised or generated from a user-facing report.
Key takeaway
Prefer the underlying provider records with field definitions, using summaries to explain them rather than allowing a simplified narrative to replace the evidential source.