A log-integrity feature can deliver signed digest records that name and hash audit files. Enabling delivery of those digests is only the first step; a verifier must check signatures, file hashes, and continuity for the requested time range. An intact digest chain speaks to delivered log files, while selector coverage and delivery health determine whether the events of interest were captured at all. These are separate questions in an investigation.
Audit log integrity: verify delivery and digest continuity
Operational decision
A finance account writes audit records into a restricted central bucket. Enable digest delivery before the test window, record the trail configuration and event selectors, and run a controlled role-assumption and object-read probe. After delivery, validate the digest chain over that bounded window with an independent read role. Verify the probe events are present and their request identifiers match the test record. In a disposable copy, alter one audit file and remove another; the validation process should report the tampering or gap rather than silently accepting the directory. Simulate a bucket-policy denial and show how delivery health and missing digest periods appear. Keep the digest bucket access path separate from the roles whose actions it records, and retain key material needed to verify signatures for the full investigation period. Do not make an incident claim from one successful file hash: record the covered accounts, regions, dates, selected event classes, and any interval when validation or delivery was disabled. A negative validation result should trigger preservation of evidence before repair automation overwrites the test artifacts.
Finance audit-evidence acceptance
Window: UTC start and end recorded
Coverage: accounts, regions, event selectors
Digest: signature and chain verified
Files: recorded hashes match delivered objects
Probe: role assumption and object read located
Gap: missing delivery or disabled validation reported
Custody: independent read role and retained resultsCost and verification
Validating F log files requires at least O(F) hash checks and reads over their bytes; digest signatures add smaller fixed cryptographic work per digest. This has retrieval and compute cost, but a sampling-only check cannot establish continuity across the whole interval. Measure unverified hours, delivery lag, validation failures, and time to explain a missing probe. A valid chain does not compensate for a selector that never recorded the object operation.
Common Mistakes
- Do not call digest delivery the same as digest validation.
- Do not treat an intact file chain as proof every API action was selected.
- Do not ignore a disabled or undelivered interval in an incident timeline.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Audit trails: prove which data-plane actions are recorded
- Immutable backup retention: protect recovery copies from deletion
- Log pipelines: preserve incident evidence without ingesting secrets
- Incident reviews: turn a timeline into tested corrective work
