What records might exist for this type of infrastructure?¶
Different infrastructure creates different records. Start with what the system could plausibly have seen; do not assume that a provider keeps every possible field.
A practical map¶
| Infrastructure | Possible records |
|---|---|
| Broadband | Allocation, subscriber, session and address-assignment records |
| Mobile or CGNAT | Subscriber, translated address, source port, protocol and session records |
| VPN or proxy | Account, connection, allocation and abuse records |
| Cloud or VPS | Tenant, virtual-machine, management, network-flow and billing records |
| Public Wi-Fi | Authentication, DHCP, access-point and session records |
| Website or platform | Account, event, request, session and application records |
The table identifies questions to ask, not records that are guaranteed to exist.
Ask about time and retention¶
For each record, establish:
- what period it covers;
- the timestamp and time zone;
- the fields retained;
- whether the record was generated automatically;
- how long it is kept; and
- whether it has been overwritten or deleted.
Keep the answer narrow¶
A provider response may establish that a connection or tenant existed. It may not establish who controlled the device or account at every moment.
Why this matters
The absence of a record is not automatically evidence that an event did not happen. It may reflect retention, configuration, scope or a request that did not identify the right event.
The point to remember
Match the requested record to the infrastructure, event and time. Ask what existed before assuming what should exist.