How should missing records be reported?¶
Missing records should be reported by stating exactly what was not found, where it was expected and what enquiries were made to explain the gap.
Absence should not be turned automatically into proof of non-occurrence or deletion.
Avoid the dangerous assumption¶
The dangerous assumption is that a missing entry has one obvious meaning.
It may reflect configuration, retention, filtering, collection failure, system outage, overwrite, export limits or deliberate interference.
The report should identify the source system, event type, relevant time period and dataset examined. State whether the system was expected to create that record and what evidence supports that expectation.
Explain what was known about logging settings, retention, storage, collector health, permissions and export filters. Record whether alternative sources were checked.
Use precise wording. “No matching event was located in the available export” is different from “the event did not occur”. “The relevant records had expired under routine retention” is different from “the logs were deleted”.
If the cause of the gap remains unresolved, say so. Do not fill the gap with inferred events unless they are clearly labelled as inference.
Where the absence has evidential weight, explain why the source was expected to be complete and reliable. Where that cannot be established, the absence should be treated cautiously.
Preserve evidence of the search method, query, date range and result count so the enquiry can be reviewed or repeated.
Operational takeaway¶
Report missing records by defining the expected source, search and possible explanations, and distinguish no record found from proof that no event occurred or that evidence was deliberately removed.