Skip to content
Skip to main content
Cloud Services Technical Explainer

Could cloud logging have been disabled or changed?

Yes. Logging may be enabled, reduced, redirected or disabled by configuration, subscription and system changes. The settings visible today do not establish what was recorded during the relevant period.

Reconstruct the historical configuration

Administrator audit, configuration history, billing or licence records, change tickets and provider-support material may show changes to event categories, retention, destinations or permissions. Preserve who or what made each change, its time, and the previous and new values.

Logging can also be interrupted by misconfiguration, service failure, exhausted storage or a broken forwarding connection. A drop in volume may affect one source while authentication or security systems continue recording related activity.

Look beyond the provider console

Organisations often forward events to a security platform, archive or local collector. Those copies may survive after provider retention expires or logging is reconfigured. Check the forwarding status and whether the destination transformed, filtered or dropped events.

A gap following suspicious activity may be relevant, but timing alone does not prove concealment. Operational mistakes, product changes and licence transitions are common alternative explanations. Compare configuration evidence with wider activity and identify what, if anything, continued to be logged.

If administrator logging is itself incomplete, use independent change-management, billing, support and collector records cautiously to reconstruct the likely state.

The point to remember

Establish the logging configuration that applied at the time, trace any changes and check secondary copies before interpreting a gap as either technical failure or deliberate action.

Reference: CLD-135Cloud Services