Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is log clearing?

Log clearing deletes, truncates or resets recorded events. It may support concealment, but maintenance, testing, rebuild and storage management can also produce a legitimate clear.

Preserve the clearing event

Identify the account and process, command or tool, time, affected source and records immediately before and after. Check service state, storage, collection health and log size to exclude rollover or failure.

Central, provider, backup or security-platform copies may retain both the earlier events and evidence that the local log was cleared. Establish whether forwarding continued and whether the account changed logging settings beforehand.

Keep concealment and incident attribution separate

Timing immediately after suspicious activity can support an inference of concealment; scheduled maintenance may explain the same operation. State the context and authority.

Even deliberate clearing does not prove the same controller committed every underlying event. Report who or what technical identity acted, the scope removed and which copies survive.

Key takeaway

Prove the clear operation, affected records and surviving copies, then assess concealment without equating the clearing account with the wider offender.

Reference: CIM-221Cyber Incidents & Offender Methods