What does a firewall log actually show?¶
A firewall log records an observation and a decision made at one point in a network. It does not necessarily record every packet or every communication.
Read the fields together¶
| Field | Question to ask |
|---|---|
| Timestamp | What time standard and clock accuracy apply? |
| Source and destination | Where was the firewall positioned and which direction was traffic moving? |
| Ports and protocol | What communication was described? |
| Action | Was it allowed, blocked, dropped or rejected? |
| Rule or policy | Which configuration produced the decision? |
| Interface or zone | Which network boundary did the traffic cross? |
| Session, bytes or duration | Is this one packet or evidence of a larger exchange? |
A source address may be private inside the network or public outside it. NAT may also mean the value is not the original device address.
What the log does not automatically show¶
An allowed entry does not prove that the destination accepted the connection, that an application completed an action or that a person used the device. A blocked entry does not prove malicious intent.
Logging may be selective. Missing entries may reflect configuration, retention or the firewall’s position rather than absence of traffic.
Example¶
source=10.0.0.25:51514 destination=203.0.113.10:443
protocol=TCP action=allowed
This supports the narrow statement that the firewall allowed traffic matching those values. Further records are needed to explain the user, content or final outcome.
The point to remember
Establish what this firewall could see and record before treating one line as a complete account of the communication.