Could a collector delay or lose events?¶
Yes. Buffering, outages, overload, API limits, permissions and full queues can delay, reorder or drop delivery. A central-platform gap does not therefore prove the source event never existed.
Delivery order can distort chronology¶
After reconnection, old events may arrive together or after newer records while retaining original source time. Buffers can overflow, files roll over and unreliable protocols may not retry. Source logging can also fail independently.
Compare pipeline timestamps and health¶
Preserve event, collection and ingestion times, collector queues, errors, retry and outage or upgrade history. Check the source system while records remain.
Distinguish source gap from collection gap before inferring deletion or absence. Sort by the time field appropriate to the investigative question.
The point to remember
Collector delay and loss can change apparent sequence and completeness, so central records must be checked against source and pipeline health.