For the complete documentation index, see llms.txt. This page is also available as Markdown.

Retaining Original Exhibits

Disclaimer: I'm not a lawyer. Seek legal advice or consult your internal Legal/HR department to understand your organisation's or country's legislative or procedural requirements.

Civil litigation and Fair Work matters are can be decided on electronic evidence pulled from SIEM platforms, proxies, and endpoint telemetry. Unlike criminal matters, where evidence handling is usually governed by a documented forensic process from the outset, civil and workplace investigations are often run by HR or IT without device seizure, imaging, or exhibit retention considerations.

I've written this article to highlight why I believe SIEM (or equivelant) export alone is insufficient, what the Evidence Act (piece of Australian Commonwealth legislation) actually does and doesn't require, highlighting matters illustrating the shortfall between derived and source evidence, and the governance controls that prevent the problem occurring in the first place.

TL;DR - I strongly support (where it is lawful, permissible, practical, and operationally suitable) seizing and retaining original exhibits to support civil and disciplinary matters until the matter is resolved.

A SIEM export is not a replacement for the original exhibit

A Splunk export, or equivalent from any SIEM, is a query result built from parsed and indexed data. It is not the underlying record. Treating it as the primary exhibit creates several problems if challenged:

Issue
Why it matters / the risk

Export is a query result

Search terms, time window, and excluded fields can all be questioned. If you can't reproduce the result from the raw index, you can't answer a challenge to it.

Short retention periods

Proxy, firewall, and gateway logs commonly age out at 30-90 days. Dispute timelines routinely exceed that.

Parsing errors

Misconfigured sourcetypes, timezone offsets, and dropped malformed lines don't appear in a dashboard. They appear when someone asks you to reproduce the result from source.

Device is a separate evidentiary source

Local browser history, application logs, and OS artefacts can corroborate or contradict network-layer data.

I believe there should be working rule. if you can query it in Splunk, the raw log source behind it should already be under extended retention, and if the device is still in your possession, it should be imaged before it's wiped, reissued, and returned to circulation.

I'm not suggesting that SIEM data is a direct replacement for EDR data, and isn't a direct replacement for analysing the original device. These data sources (as highlighted below in Kumar v Hansen Corporation Pty Ltd) often work together to build a complete picture.

Retention vs Dispute Timelines

Claim type
Typical lodgement/limitation window
Common hot-tier log retention

Unfair dismissal (Fair Work Act s.394)

~21 days to lodge

30-90 days

General protections / discrimination

~21 days (dismissal) to 6 years (some state discrimination claims)

30-90 days

Contract/negligence (civil)

Statutory limitation periods, typically 6 years

30-90 days

When you consider the potential time between the misconduct, the start of the investigation, the conclusion of the investigation, the dismissal/disciplinary outcome, and the matter finally being heard in court, it becomes immediately apparent that a 30-60-90 day log retention period, coupled with a lack of consideration to retain the original exhibit, it can put a party in a difficult and potentially indefensible position.

Evidence Act

Section 51 of the Evidence Act 1995 (Cth), mirrored in the uniform Evidence Acts across Australia's states and territories, abolishing the common law original document rule. A party is not required to produce an original to prove the contents of a document. A copy, printout, or forensic export is admissible in principle.

This resolves an admissibility question however it does not resolve a reliability question.

Sections 146 and 147 create a rebuttable presumption that a device or process, if it ordinarily functions correctly, produced an accurate result on the occasion in question. The presumption is exactly as strong as your ability to defend it once challenged. If the only exhibit is a summary export with no path back to raw source, there is nothing left to defend it with.

In the Fair Work Commission specifically, the position is more exposed and arguably less defensible. The Commission is not bound by the rules of evidence, but has stated it cannot ignore them where doing so would cause unfairness between the parties (see FWC, Evidence).

Case References

Kumar v Hansen Corporation Pty Ltd [2026]

Employer's case relied on records from Microsoft Entra, Zscaler, and SentinelOne, showing the employee was not active on his device during hours logged as client work. Accepted by the Commission because the data was corroborated across independent systems rather than resting on a single export. This is the standard to build toward from the start of an investigation, not retrofit once an application is filed.

Raghib v Stantec Australia Pty Ltd [2025] FWC 2335

Employee's unfair dismissal claim relied on a screenshot of a text message. When the underlying screen recording was broken into individual frames, the sending phone number matched the employee's own work mobile. The device (not the screenshot) settled the question. A derived artefact the applicant controlled, with no way to check it against source, nearly succeeded.

Governance Controls

Log retention: Align hot-tier retention for identity, EDR, proxy, and email gateway logs to the limitation periods of the claim types the organisation is exposed to, not to storage cost.

12 months minimum for anything touching user activity, with cold-tier archival beyond that.

Acceptable Use Policy: State explicitly which systems are monitored, what data is logged, and the business reason for it. Vague "may monitor" language is a weak foundation once that monitoring becomes the primary exhibit. Explicit acceptable use policy language supports both the reliability of the data and a fairness argument that the employee had reasonable notice of the monitoring in place.

Litigation hold triggers: Legal-issued hold notices are frequently too late for short-retention logs. Build a technical trigger, HR/Legal escalation or SOC-detected anomaly initiates an immediate extended retention hold and, where applicable, a forensic image of the relevant device, independent of whether legal proceedings have formally started.

Chain of custody for log queries: Applies to log queries and pulls, not only physical devices. Record who queried what, in which tool, over what time range. Preserve the query itself alongside the export. Hash the export where practical.

Retention of unhelpful material: Do not allow retention policy to quietly age out material that doesn't support the preferred narrative. A conveniently missing log invites an adverse inference that costs more than the log itself ever would have.

Internal vs External Capability

Not every step in this process belongs inside the organisation, and getting that boundary wrong presents another potential source of exposure.

What internal teams should handle

  • Preservation: extending log retention, isolating a device from reissue, disabling auto-wipe or auto-reimage policies on the asset.

  • Initial triage: identifying which systems are relevant and what timeframe is in scope.

  • Documentation: recording who did what and when, from the moment the issue was identified.

What should go to an external, qualified provider

  • Forensic acquisition of the device itself (imaging, hashing, write-blocking)

  • Analysis intended to support an expert/opinion evidence report

  • Any engagement where the output may be relied on in the Commission, a court, or arbitration/mediation.

The reason for the split isn't simply a matter of ticking a compliance box. An expert report carries weight partly because of the qualifications and experience of the person who produced it. Internal IT staff acquiring a device without formal forensic training, without a write-blocker, without a documented methodology, creates an obvious avenue for challenge.

The classic chain of custody/integrity matter results in a question of not "is this data accurate," but "was this person qualified to collect it without altering it." That challenge is often easier to win for the other side than one aimed at the data itself, and it can undermine an otherwise solid exhibit for no reason other than who touched it first.

Acquisition and analysis intended for tribunal or court use should sit with a provider operating to a recognised standard.

I am not suggesting that internal SOC or IT staff can't do good work. It's a recognition that "good work" and "work whose provenance survives cross-examination" are not automatically the same thing, and the second one is what the matter actually needs.

Agreements to have in place before an incident, not during one

  • A standing engagement or panel arrangement with a DFIR provider, so acquisition doesn't wait on a procurement cycle while logs roll off and devices get reissued

  • Clear scope in the agreement: what triggers engagement (SOC alert, HR escalation, legal instruction), including what the provider is authorised to acquire, and expected turnaround

  • Chain of custody and reporting requirements specified in the agreement itself, not left to the provider's discretion.

  • Engagement routed through legal counsel where the matter may result in dismissal or litigation, so legal professional privilege can attach to the resulting report where appropriate.

  • Confidentiality and data handling terms consistent with the organisation's own privacy obligations, since the provider will be handling the same personal information the organisation is responsible for.

Get this arrangement in place before it's needed. The time and delay between "we think we might need a forensic provider" and "we have an engaged provider imaging the device" is the period of time in which logs roll off and devices get reissued to the next starter.


Summary

Section 51 already settled the admissibility argument over originals. What decides civil and tribunal matters now is reliability and fairness, and both are earned by retention and process decisions made before a dispute exists, not by argument made once it does. Set retention against dispute timelines, image devices before they're reissued, keep the AUP explicit, build litigation hold triggers into the SOC runbook rather than the legal team's inbox, and know where the internal team's role ends. Preservation and triage can be handled internally, but acquisition and expert analysis belongs with a suitably qualified and experience internal resource and where not available, an external provider - ideally engaged before the matter starts, not after.

References

  • Evidence Act 1995 (Cth) s 51, 146, 147

  • Fair Work Act 2009 (Cth) s 394

  • Fair Work Commission, Evidence (fwc.gov.au/evidence-2)

  • Kumar v Hansen Corporation Pty Ltd [2026] FWC

  • Raghib v Stantec Australia Pty Ltd [2025] FWC 2335

  • Raghib v Stantec Australia Pty Ltd [2025] FWCFB 218

Last updated