Skip to content

Glossary · Cybersecurity

Audit log

Also called: Audit trail, Access log, Event log

An audit log is a system-generated record of who did what, when, and from where. In litigation it is unusually valuable because it is machine-generated rather than authored — which means it is generally not hearsay, and it records activity that no document describes.

Why it carries disproportionate weight

Documents record what someone chose to write. Logs record what systems observed, without editorial intent, contemporaneously, and usually without anyone anticipating that the record would matter.

That has an evidentiary consequence. Machine-generated records are generally not hearsay, because there is no human declarant making an assertion — the reliability question about them is authentication rather than an exception. It also has a practical consequence: logs frequently contradict the account a party gives, and they do so without a witness having to be disbelieved.

Retention is the constraint that decides cases

The most common finding in an investigation is that the relevant period is no longer covered.

Defaults are short. Cloud platform audit logs frequently retain for weeks or a few months, some detailed logging is only available on higher licence tiers, firewall and proxy logs rotate on volume rather than time, and endpoint telemetry is typically measured in weeks. Meanwhile the intrusions and insider activity that matter most are usually discovered long after they began.

Extending retention is cheap, has to be done in advance, and is the single most useful preparatory step an organisation can take for any future investigation. Most have never made the decision — not because they decided against it, but because nobody was asked.

What to preserve first

In the opening hours of an incident, the ordering follows expiry rather than importance:

  • Authentication logs, which establish account compromise and lateral movement.
  • Network egress records from firewalls and proxies — the primary evidence of whether data left, which is the finding everything else depends on.
  • Endpoint detection telemetry, often the shortest-lived and the richest.
  • Cloud audit logs, for access to data held off-premises.
  • Application logs, for the specific systems in scope.

Absence is evidence too

A cleared event log is itself a logged event, and the log's own record of being cleared is one of the first things an examiner looks for. Gaps in an otherwise continuous record, or a logging service disabled during exactly the window in dispute, are findings rather than dead ends.

This is also why arguing that logs simply do not exist is worth verifying before saying it. Being contradicted on that point is considerably worse than the gap itself.

Getting them admitted

Logs are ordinarily offered as business records, and the foundation is not automatic: someone has to establish how the system generates and retains them, that it was operating normally, and how the produced extract was created. Preserving the raw log file alongside any exported or filtered version matters here — an extract that cannot be tied back to the source invites the argument that it was selected rather than produced.

From our work

Dealing with audit log in a live matter?

Our examiners and testifying experts work these questions for a living. Tell us what you're facing.

Reviewed by Law & Forensics. See our editorial standards.