Skip to content
Skip to main content
Logs, Records & Provider Evidence Operational Explainer

Could retention have expired?

Yes. Logs are often deleted, archived or removed from normal access after a time or storage limit. An active account does not mean all of its historical audit data remains available.

Retention differs by record and location

Sign-in, security, mailbox, API and administrator events may have different periods. Licence and configuration can affect them, and a SIEM or archive may keep a copy after the provider source expires. Dashboard absence may also mean cold storage rather than deletion.

The relevant policy is the one in force when the event was stored and when collection was requested, not today's published period.

Work from dates and alternate copies

Record event date, request date, historical period, licence, configuration and expected expiry. Ask whether policy changed, archives or backups exist, and whether preservation was applied before expiry.

Routine expiration is not evidence of wrongdoing. Where original data has aged out, check endpoints, identity services, gateways, network systems and central monitoring for independently retained stages.

The point to remember

Establish historical retention early and seek alternative copies before volatile records expire.

Reference: LOG-123Logs, Records & Provider Evidence