Could cloud logging have been disabled or changed?¶
Yes. Cloud logging may be disabled, reduced, redirected or changed.
Evidential caution: that the current logging configuration applied throughout the relevant period.
What this means¶
An administrator may enable or disable audit features, change retention, alter export destinations or downgrade the subscription.
Logging can also fail because of misconfiguration, service interruption or licence changes.
Equally, a deliberate reduction in logging may be relevant where it follows suspicious access or other compromise indicators.
Where logs are forwarded to another platform, check whether the provider record disappeared but the forwarded copy survived.
Where administrator logging itself is incomplete, configuration changes may need to be inferred cautiously from billing, help-desk, security-platform or provider-support records.
Where the logging change affects a critical period, establish whether any secondary system received copies before the change. Security tools, archives and local collectors may preserve evidence no longer visible in the cloud console.
What to check or do next¶
- Investigators should identify the historical logging settings, not only the current state.
- Check administrator audit records, configuration history, change tickets, security-platform settings and subscription records.
- Look for sudden changes in event volume, missing categories or a gap beginning after an administrator action.
- Preserve evidence of configuration changes, including who or what made them, the time, previous value and new value.
- Use wider records to determine whether activity continued during the logging gap.
Evidential limits¶
Do not assume that a logging gap proves deliberate concealment. Operational mistakes and product changes are common.
Operational takeaway
Cloud logging can change over time, so establish the historical configuration and explain whether any gap reflects policy, failure, licence change or potentially deliberate action.