How do I identify which session performed a cloud action?¶
Work outwards from the action using session or correlation IDs, then match authentication, token, application, device and connection records. The login nearest in time is not necessarily the session that performed it.
Anchor the action first¶
Preserve the event ID, account, resource, original time and zone, application/client ID, source address, device fields, operation and result. Identify whether the route was a browser, mobile app, sync client, API or service account.
Use an exposed session, request or correlation identifier as the strongest join. Locate the corresponding session creation, token issue or refresh, activity and revocation events. A session may have begun days earlier, and several can remain active on the same account.
Rank contextual matches carefully¶
Where no common ID is available, compare account, application, device, address and timing as a combination. A changed IP does not prove a new session because mobile routing, VPNs and roaming alter connections; similar device text does not prove continuity either.
Check local browser, token and application artefacts where available. Allow for provider processing delay and time conversion before treating close events as separate.
If several sessions remain possible, record and rank the candidates by the strength of each link rather than selecting one because the interface displays a single account name.
The point to remember
Link an action to its session through stable event and correlation data, using timing and device context only with stated limitations.