Logs an attacker can edit are not evidence
If a host's logs live only on that host, anyone with administrative access on it controls the record of what they did there.
Local logs answer to whoever holds administrative rights on the machine.
That is not a flaw to fix, it is what local means. An account with sufficient privilege can clear a log, disable the service writing it, or change what gets recorded, and every one of those is a supported operation rather than an exploit. So the record of an intrusion sits inside the blast radius of that intrusion.
Forwarding is the answer, and it is a small one. Ship events off the host, to somewhere the host’s administrators do not control, and the copy that already left is beyond reach. You are not making the local log tamper-proof. You are making it not matter.
Two details decide how much this actually buys you. How quickly events leave, because anything written but not yet shipped is still exposed. And whether the destination is genuinely outside the compromised administrative boundary, which it is not if the same domain accounts administer both.
There is a bonus. Clearing a log is itself an event, and it forwards like any other. On most estates that event is rare and boring, which makes it one of the higher quality signals available.
Check two things. Whether your critical hosts forward at all, and whether the account that owns them can also reach where the logs land.
CHECK YOURSELF
An attacker gains administrative access to a server and clears its event log. That server forwards its logs to your platform. What can you still establish?
SHOW THE ANSWER
Everything forwarded before the clear, and the clear itself
Why. Forwarding means the record left the host before the attacker touched it, and a copy somewhere else is not theirs to edit. Clearing a log usually generates its own event, which forwards too and is a strong signal in its own right. The last answer overstates what forwarding does: there is always a lag between an event being written and being shipped, so anything generated inside that window can still be lost. That lag is the thing worth knowing the size of.