Skip to content
LOG-123 Logs, Records & Provider Evidence

Could retention have expired?

Yes. Log retention can expire before investigators request the records.

Many systems keep events only for a configured period and then delete, archive or make them inaccessible.

Avoid the dangerous assumption

The dangerous assumption is that a provider or organisation can always retrieve historical logs because the account or system still exists.

That is often wrong.

Retention may be measured in days, weeks, months or storage volume. Different log types may have different periods. Basic account activity may remain while detailed audit or security events expire much sooner.

Cloud services may vary retention by licence, subscription or configuration. An organisation may also keep data in a SIEM after the source system has deleted it, or retain archives that are not visible in the normal dashboard.

Investigators should establish the retention policy that applied at the relevant time, not merely the current policy. Ask whether the period was changed, whether archives existed and whether legal hold or preservation functions were available.

Record the date of the event, the date of the request and the expected expiry point. Where time remains, preservation should be considered promptly through the appropriate lawful and organisational process.

Expired retention is not evidence of wrongdoing. It may reflect routine policy. But failure to act promptly can result in avoidable loss of important evidence.

Check alternative sources such as endpoints, email gateways, identity providers, network systems, backups and central monitoring platforms.

Operational takeaway

Retention may expire while an investigation is developing, so investigators should identify relevant periods early, preserve volatile sources promptly and seek alternative records where the original data has aged out.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.