Skip to content
Skip to main content
IP Addresses & Networks Technical Checklist

What information should come with an IP address?

An IP address is most useful when it stays attached to the record that explains where it came from, when it was recorded and what happened.

Keep the core context

Retain the complete address exactly as recorded, the recording system, original record or best export, event and outcome, full date and time, time zone or UTC offset, and field label.

If several addresses appear, keep them together with their labels.

Keep connection detail

Also retain source and destination addresses, source and destination ports, protocol, account, device, request or session identifier, event status and surrounding entries.

Not every system records every field. Preserve what exists; do not invent what is absent.

Why time and ports matter

Providers may allocate or share addresses over time, so a precise event timestamp is more useful than a date alone. In shared-address environments such as CGNAT, the public source port and protocol may help separate simultaneous connections. They must come from the same event.

See what date, time and time zone the timestamp represents and what a source port is.

The minimum useful sentence

[System] recorded [event and outcome] involving [IP address] at [date, time and time zone]. The record also contains [ports, protocol and identifiers].

If a detail is unavailable, say so. Do not present an incomplete record as complete.

Minimum useful package

Keep the address, system, event, exact time, time zone, field labels and available connection details together.

Reference: IP-021IP Addresses & Networks