Your logs are shorter than you think
Most sources cap field length. The event still arrives and still parses, with nothing marking the point where the text stopped.
Command lines get cut. Not by an attacker, by the logging.
Most telemetry sources cap field length somewhere. A process creation event may carry the first few hundred characters of a command line and drop the rest. Cloud audit logs truncate large request bodies. Syslog has a line limit that middleboxes enforce inconsistently. The event still arrives, still parses, and still looks complete, because nothing marks the point where the text stopped.
This matters because the interesting part is usually at the end. A long encoded blob. A URL. A flag that changes what the command actually does. If your rule matches a substring living past the cut, it will never fire, and it will never tell you why.
The tell is boring and easy to find. Sort your process events by command-line length and look at the top of the list. If a suspicious number of them land on exactly the same value, that value is your limit rather than your data.
Then decide what to do, because the answer is rarely to log more. Sometimes the cap is configurable. Sometimes you match on something else entirely, like the parent process or a loaded module. Sometimes you accept the limit and write it down, so the next person does not lose a day debugging a rule that was never going to match.
Go and find your longest command line. If it is a round number, you have found the ceiling.
CHECK YOURSELF
A rule matching a string that appears late in a long command line has never fired, although the activity occurs and other rules matching the start of that same command line fire normally. What do you check first?
SHOW THE ANSWER
Whether the command-line field is truncated before your string
Why. Rules firing on the start of the same command line prove the field exists and is populated, which rules out logging being off and the account being suppressed. What is left is length. Field caps cut the tail without marking where they stopped, so the event looks complete and your match simply is not inside it. Sorting events by command-line length and looking for a repeated maximum finds the ceiling in about a minute.