Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is log tampering?

Log tampering is deliberate interference with record creation, content, timing, storage or availability intended to mislead or conceal. It includes much more than deleting a log file.

Interference can occur throughout the pipeline

Someone may disable an event category, alter the clock, edit or clear records, stop a collector, redirect forwarding or generate misleading entries. Required access may be local administration, cloud privilege, application rights or control of the collection service.

Append-only storage, central forwarding, signatures and replication can limit some methods and create independent comparison points.

Indicators need a mechanism and context

Change audits, broken sequences, altered metadata, unexplained service stoppage and disagreement between source and remote copies may support tampering. Rotation, migration, corruption and maintenance can create similar symptoms.

Preserve original files, metadata, configuration and independent copies without unnecessary resaving. Specialist examination may be needed for signatures, internal formats or file-system artefacts. Conclude tampering only where the evidence supports deliberate mechanism and access, not merely an unexplained gap.

The point to remember

Log tampering is deliberate pipeline interference and should be concluded from supported mechanism, access and indicators.

Reference: LOG-127Logs, Records & Provider Evidence