Insider Threat Matrix™Insider Threat Matrix™
  • ID: AF034.005
  • Created: 05th August 2026
  • Updated: 05th August 2026
  • Contributor: The ITM Team

Disable Log Forwarding and Collection

A subject disables or interferes with the mechanisms used to transmit, collect, process, or ingest logs into a centralized repository, archive, data lake, or Security Information and Event Management platform.

 

The subject may stop or reconfigure a forwarding agent, disable syslog transmission, remove a collector subscription, change a destination address, revoke a pipeline identity, block required network traffic, alter routing or filtering rules, or suppress specific event sources before ingestion. Local records may continue to exist even though investigators lose centralized visibility.

 

Investigators should identify missing source heartbeats, ingestion gaps, forwarding-agent health changes, configuration modifications, authentication failures, queue backlogs, rejected events, and discrepancies between local records and centrally retained data.