Could logging have been disabled?¶
Yes. Logging may be off for a whole product or selected event types because it was never enabled, was deliberately configured that way, failed or was changed. A gap alone does not establish deliberate interference.
Detailed logging is not always the default¶
Audit, database, mailbox and administrative records may depend on configuration, licence or storage. Teams may reduce noisy logging for cost or performance. Upgrades, service faults and policy errors can also stop collection; an attacker is another possible cause, not the only one.
The current setting does not prove what applied historically, especially after incident response.
Seek evidence of historical state and change¶
Preserve configuration and policy history, administrator audits, service status, tickets and deployment records. A change event, command or simultaneous gap across expected categories may establish when logging stopped and which technical identity acted.
Separate “logging was disabled” from “no records are available”. If the historical state cannot be shown, use the narrower description and explain the missing evidence rather than attributing the gap.
The point to remember
Prove historical logging state and any change before explaining missing records as disabled or deliberately suppressed.