Skip to content
LOG-144 Logs, Records & Provider Evidence

How should gaps in a timeline be shown?

Gaps in a timeline should be shown openly rather than silently compressed or filled with assumptions.

A gap may itself be relevant, but its cause must not be invented.

Avoid the dangerous assumption

The dangerous assumption is that the absence of entries means nothing happened during that period.

It may instead reflect missing, uncollected or unavailable records.

A gap can arise because logging was disabled, retention expired, storage rolled over, a collector failed, a device was offline or the selected dataset did not cover the period.

The timeline should mark the start and end of the gap and identify which source or event type is missing. It should distinguish a confirmed period of no recorded activity from a period where records are unavailable.

Investigators should record what was searched, what should normally exist and what enquiries were made. If another source continues through the gap, include those records rather than presenting the entire period as empty.

Do not insert estimated events into the main sequence as though they were recorded facts. Where an event is inferred, label it clearly and explain the basis.

If the gap affects a significant conclusion, show the limitation prominently. A clean-looking timeline is less important than an honest one.

Preserve evidence of outages, maintenance, retention and collection health that may explain the missing period. Where no explanation is established, report the gap as unresolved.

Operational takeaway

Timeline gaps should be visible, source-specific and accurately labelled, distinguishing no recorded activity from unavailable evidence and separating supported inference from recorded fact.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.