Does the absence of a log entry prove that an event did not happen?¶
Usually not. It proves that no matching entry was found in the material searched. Absence weighs against an event only when that event should reliably have been recorded, retained and included in a complete search.
Logging has several possible failure points¶
The event type may be disabled or filtered, recorded in another component, delayed, overwritten or outside the licensed retention period. A client can fail before reaching the server, and collectors, parsers or exports can omit otherwise existing records.
Alternative systems may still record a related stage even where the expected application entry is absent.
Establish the expectation before using absence¶
Identify the component and condition that should create the record. Verify historical configuration, retention, source health, collection coverage, query scope and export limits. Comparable successful events can help test how consistently the system logs them.
If a well-understood system reliably records every qualifying action and complete source data is available, the gap may be meaningful negative evidence. State the established conditions and avoid turning a search result into broader proof than they support.
The point to remember
Missing entries become probative only after reliable logging, retention, coverage and search completeness are established.