Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

Could the relevant event type have been filtered out?

Yes. Filtering can exclude an event at creation, forwarding, SIEM ingestion, search or export. Its absence from the material received does not establish that no source record exists.

Visibility narrows at each layer

A source may record only selected categories, while collectors and connectors drop events by severity, user or type. Dashboard time ranges, saved exclusions and search terms can hide stored records. Exports may contain only visible columns, one page or a result limit.

Names also vary: a search for “login” may miss token validation, federation or session-refresh codes.

Trace the query back to the source

Record source settings, forwarding policies, connector filters, query text, time zone, result count and export options. Identify the native event code and request a broader source export where proportionate.

Distinguish filtered from deleted data. A downstream system may never have received an event that remains available in its source or archive, so each layer needs its own coverage conclusion.

The point to remember

Examine every filter between event creation and reviewed output before treating an absent result as an absent record.

Reference: LOG-122Logs, Records & Provider Evidence