Reading silence in log exports
A quiet export can mean a quiet system, a broken collector, or a filter applied before the file left the building.
Silence is a fact about the file, not a fact about the network. When a collector produces no rows for an hour, the honest sentence is that the export contains no rows for that hour. Whether packets moved anyway is a separate question the file cannot answer.
In anomaly detection reviews we mark three kinds of quiet: expected quiet (a system that only speaks on weekdays), collector quiet (heartbeats stop), and filtered quiet (the export was built with a search that dropped the interesting rows). Only the third kind is usually recoverable, and only if someone still holds the unfiltered source.
Incident visibility reporting spends a full section on coverage gaps for this reason. Stakeholders who wanted a complete movie receive a list of missing reels instead. That list is often the most useful page in the packet, because it tells the next collector what to keep.
Do not backfill silence with threat-intelligence color. A campaign name from a public blog is not a substitute for a timestamped row.