Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

Why might an expected log entry be missing?

An entry can be absent because it was never generated, was stored elsewhere, failed to reach collection, expired or was excluded from the material examined. Deliberate deletion is only one hypothesis.

Follow the record's expected route

The source may log only selected outcomes or write the event to another file, server or tenant. The process may fail before its logging stage. Storage rotation, offline devices, connector failure, parser errors, permissions, filters and export row limits can all remove visibility later.

Each explanation affects a different point between action and reviewed output.

Define and investigate the gap precisely

Record which event was expected, what trigger and component should create it, where it should be stored and for how long. Check historical configuration, collector health, export settings and neighbouring events. Endpoint, network, identity or database records may expose another stage.

Evidence of a logging change or deletion should be sought before alleging interference. Where the route cannot be reconstructed, report the missing expected record and the enquiries made without assigning an unsupported cause.

The point to remember

Locate the point where an expected record should have been created and moved before explaining its absence.

Reference: LOG-120Logs, Records & Provider Evidence