Skip to content
LOG-129 Logs, Records & Provider Evidence

Could a gap be caused by maintenance or outage?

Yes. A maintenance period or system outage can create a genuine gap in logs without deliberate interference.

The gap may affect event creation, collection, forwarding, storage or display.

Avoid the dangerous assumption

The dangerous assumption is that every unexplained break in logging is suspicious.

Routine technical activity can produce the same result.

During maintenance, services may be stopped, devices rebooted, agents upgraded or connectors disabled. During an outage, the source system, network, collector or SIEM may be unavailable.

Some systems buffer events and forward them later. Others lose them entirely. A gap may therefore be followed by a delayed batch, or it may remain permanently empty.

Investigators should ask whether planned work, faults or incidents occurred during the relevant period. Preserve maintenance schedules, change tickets, outage alerts, service-health records and restart events.

Compare several sources. If many unrelated devices stop reporting at the same time, a central outage may be more likely than individual tampering. If only one source stops, the problem may be local.

Check whether the gap aligns with reboot, upgrade or network-restoration events. Ask whether the system stores records locally while disconnected and how long the buffer lasts.

Do not assume a maintenance explanation is automatically correct merely because a change window existed. Confirm that the work could affect the relevant log and that the timing matches.

Operational takeaway

Maintenance and outages can create legitimate logging gaps, so investigators should compare service, change and collection records before treating the absence as deliberate deletion or proof that no activity occurred.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.