Skip to content
FRP-143 Fraud & Financial Crime

Could logs be lost when network equipment is powered down?

Yes. Logs and other live network records may be lost when equipment is powered down or restarted.

Avoid this assumption: Network logs are always written permanently to storage. Many routers, switches, firewalls and access points retain some records only in volatile memory.

Power loss may clear connection tables, temporary alerts, DHCP information, VPN sessions, counters, uptime and locally buffered logs.

If the equipment forwards logs to another system, shutdown may stop that forwarding before the final records are transmitted.

Before changing power state, record the appliance, display, alerts, uptime, connected ports, active sessions and visible log information.

Identify whether logs are stored locally, forwarded to a server, retained by a provider or available through a cloud-management platform.

Do not restart the equipment simply to restore service or access without considering the evidential cost.

Where the system is part of an active incident, seek network or incident-response advice quickly.

If shutdown is unavoidable, record the reason, authorisation, exact time and equipment affected.

Capture any warning that logs, sessions or configuration will be lost.

After power is restored, record the new uptime, changed addresses, reconnecting devices, missing entries and altered alerts.

Do not present post-restart logs as a complete record of the earlier period.

Where a central copy exists, preserve its scope, retention and timing separately.

Record whether the equipment has battery backup or redundant power.

Operational takeaway

Assume power loss may erase volatile network evidence, and preserve live logs, sessions, tables and forwarding arrangements before any justified shutdown or restart.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.