Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

Could a gap be caused by maintenance or outage?

Yes. Planned work or failure can interrupt event creation, forwarding, storage or display without deliberate interference. The pattern depends on where the interruption occurred and whether data was buffered.

Central and local failures leave different patterns

Maintenance can stop services, reboot hosts or upgrade agents. Outages can affect a source, network, collector or SIEM. Some components resend buffered events after recovery; others lose them, producing either a delayed batch or a permanent gap.

Simultaneous loss from many unrelated sources can point to central collection, while one affected source suggests a local cause.

Match the gap to operational evidence

Preserve change tickets, maintenance windows, service-health alerts, restarts and recovery events. Check whether the affected system normally buffers data, for how long, and whether the timing and event categories fit the proposed work or fault.

A scheduled window is not proof that it caused the gap. Confirm the actual change and affected path before adopting maintenance as the explanation.

The point to remember

Use service, change and cross-source records to determine whether a logging gap follows maintenance or outage.

Reference: LOG-129Logs, Records & Provider Evidence