Could a gap be caused by maintenance or outage?¶
Yes. A maintenance period or system outage can create a genuine gap in logs without deliberate interference.
The gap may affect event creation, collection, forwarding, storage or display.
Avoid the dangerous assumption¶
The dangerous assumption is that every unexplained break in logging is suspicious.
Routine technical activity can produce the same result.
During maintenance, services may be stopped, devices rebooted, agents upgraded or connectors disabled. During an outage, the source system, network, collector or SIEM may be unavailable.
Some systems buffer events and forward them later. Others lose them entirely. A gap may therefore be followed by a delayed batch, or it may remain permanently empty.
Investigators should ask whether planned work, faults or incidents occurred during the relevant period. Preserve maintenance schedules, change tickets, outage alerts, service-health records and restart events.
Compare several sources. If many unrelated devices stop reporting at the same time, a central outage may be more likely than individual tampering. If only one source stops, the problem may be local.
Check whether the gap aligns with reboot, upgrade or network-restoration events. Ask whether the system stores records locally while disconnected and how long the buffer lasts.
Do not assume a maintenance explanation is automatically correct merely because a change window existed. Confirm that the work could affect the relevant log and that the timing matches.
Operational takeaway¶
Maintenance and outages can create legitimate logging gaps, so investigators should compare service, change and collection records before treating the absence as deliberate deletion or proof that no activity occurred.