What might a cloud IP record show?¶
It may show the public internet address observed by the provider for a login, request, session or application event. This identifies a connection at a recorded time, not the person behind it.
Preserve the connection context¶
Keep the complete IPv4 or IPv6 address, precise timestamp and time zone, event and session IDs, application, event type and provider source. Source port and protocol can be important where supplied, particularly on shared addressing systems.
Check whether the field is the originating address or an intermediate gateway, security service or load balancer. One session may move between addresses as a mobile device roams or a network changes.
The address changes the next enquiry¶
It may relate to home broadband, mobile data, a workplace, VPN, proxy, cloud host or shared gateway. Provider ownership and subscriber/organisation records can develop the connection; device and contextual evidence develop the user.
The displayed city is derived interpretation. Preserve the address itself and treat cloud geolocation separately.
The point to remember
A cloud IP field records the connection the provider saw. Keep its exact time, event and session context before pursuing infrastructure or subscriber attribution.