What evidence may indicate log deletion?¶
Deletion may be indicated by explicit clear or delete events, file-system changes, broken record sequences, missing rotation generations or disagreement between independent copies. Absence alone is not enough.
Location of the discrepancy helps explain it¶
If a local log is absent while a remote collector retains forwarded events, loss may have occurred after forwarding. Complete local data with a central gap instead points toward collection or ingestion. Missing exports, expired source data and cleared native logs are different events.
Some platforms create a separate event when a log is cleared; its storage and survivability should be established.
Test deletion against normal lifecycle¶
Preserve directory listings, file metadata, audit-policy and service events, administrator activity, backups and provider copies. Compare the observed boundary with normal rotation, archive, maintenance, migration and restoration behaviour.
State which copy or layer appears to have been removed and the evidence for when and how. Do not elevate a missing period into deletion unless ordinary storage and collection explanations have been examined.
The point to remember
Deletion is supported by mechanism and cross-copy evidence, not simply by a period with no visible entries.