Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

Could an attacker delete or alter logs?

Yes. Sufficient privilege may allow someone to clear records, stop services, change audit policy or interfere with collection. That capability does not turn every gap or inconsistency into proof of tampering.

Routine failures can resemble interference

Retention, rotation, filtering, maintenance and collection faults all produce missing records. A tampering hypothesis becomes stronger when evidence identifies required access and a mechanism linked in time to the discrepancy.

Relevant indicators include audit-policy changes, log-clear events, privileged commands, service stoppage and sudden loss of several event types.

Compare protected and independent copies

Preserve source files and metadata, configuration history, administrative activity, collector records and provider or SIEM copies. Differences between independently stored versions can show where the record chain changed. Establish who controlled the necessary privilege and whether ordinary work explains the same events.

Use “tampered with” only when access, mechanism and effect are supported. Otherwise, report the observed gap and remaining technical explanations without assigning deliberate conduct.

The point to remember

Prove capability, mechanism and resulting inconsistency before concluding that logs were deliberately altered or suppressed.

Reference: LOG-126Logs, Records & Provider Evidence