Skip to content
Skip to main content
IP Addresses & Networks Technical Explainer

What should be preserved before relevant records disappear?

Preserve the originating event and the surrounding fields needed to interpret or match it. Then identify any platform, provider, network or device records that may change or be deleted before the correct acquisition process can take place.

The dangerous assumption is that preserving “the IP address” is enough. A bare address without an accurate time, time zone, port, event type and system context may be impossible to match later - especially where connections or public addresses are shared.

Before you start

State the investigative event and the question the records may answer.

For example:

  • Which connection accessed this account at the relevant time?
  • Which internal device used a shared public address?
  • Did several recorded events use the same infrastructure?
  • What records are needed to test a claimed VPN or workplace connection?

Preservation should be proportionate to that question. It is not a reason to retain every possible record without a defined purpose.

Steps

1. Preserve the originating record

Keep the original log entry, message, alert or export that contains the address. Retain its structure and field labels rather than copying the IP address into a note.

Capture, where available:

  • complete timestamp and time zone;
  • source and destination addresses;
  • source and destination ports;
  • transport protocol;
  • account, event and session identifiers;
  • success, failure or event status;
  • system and log source; and
  • enough surrounding entries to interpret the event.

2. Confirm which fields are needed for a match

A public IP address and time may sometimes be sufficient to direct an enquiry. In shared-address environments, the visible source port can be essential. Local networks may instead require translation, DHCP, authentication or device-assignment records.

Do not discard fields merely because their meaning is not yet clear. Ask the system owner or a specialist which values connect one layer of records to the next.

3. Map the other likely record holders

Depending on the event, relevant records may sit with:

  • the platform that recorded the activity;
  • an internet or mobile provider;
  • a workplace, school, hotel or public Wi-Fi operator;
  • a VPN, proxy, cloud or hosting provider;
  • local firewall, proxy, DHCP or authentication systems; and
  • a relevant device or application.

The existence, detail and retention of records vary. Establish what each system is likely to hold rather than assuming a provider can recreate the entire path.

4. Consider a preservation action

A preservation step asks that existing data within a defined scope is not routinely deleted while the proper process for obtaining it is considered.

It does not:

  • prove that useful data exists;
  • disclose the records;
  • validate their interpretation; or
  • replace the authority and process needed to acquire them.

Use the appropriate organisational and legal process for the record holder and jurisdiction.

5. Protect changing device and local data

Relevant browser history, caches, application records and temporary network information may change through ordinary use. Where device evidence matters, obtain specialist advice early if isolation, seizure or forensic acquisition may be required.

Do not improvise technical actions that could alter the very material you are trying to protect.

Record and retain

Document:

  • what was preserved and by whom;
  • the systems, accounts, devices and time period covered;
  • the time zone used;
  • the precise identifiers supplied;
  • any confirmation, reference number or limitation received;
  • when the preservation may expire or require review; and
  • the decision to preserve - or not preserve - and its rationale.

This record keeps preservation, later acquisition and evidential interpretation distinct.

Stop or escalate when

Seek specialist or supervisory support when:

  • there is an immediate safeguarding or operational risk;
  • relevant records appear short-lived;
  • the event involves CGN, multiple translations or an unclear proxy chain;
  • you cannot identify which timestamp, port or address is relevant;
  • a device may need urgent protection; or
  • the proposed scope is unusually broad or difficult to justify.

Operational takeaway

Preserve the complete event and its matching fields - not just the IP address. Record the scope precisely, and keep preservation separate from acquisition and interpretation.

Reference: IP-076IP Addresses & Networks