Skip to content
Skip to main content
IP Addresses & Networks Technical Explainer

What does a firewall log actually show?

A firewall log records an observation and a decision made at one point in a network. It does not necessarily record every packet or every communication.

Read the fields together

Field Question to ask
Timestamp What time standard and clock accuracy apply?
Source and destination Where was the firewall positioned and which direction was traffic moving?
Ports and protocol What communication was described?
Action Was it allowed, blocked, dropped or rejected?
Rule or policy Which configuration produced the decision?
Interface or zone Which network boundary did the traffic cross?
Session, bytes or duration Is this one packet or evidence of a larger exchange?

A source address may be private inside the network or public outside it. NAT may also mean the value is not the original device address.

What the log does not automatically show

An allowed entry does not prove that the destination accepted the connection, that an application completed an action or that a person used the device. A blocked entry does not prove malicious intent.

Logging may be selective. Missing entries may reflect configuration, retention or the firewall’s position rather than absence of traffic.

Example

source=10.0.0.25:51514 destination=203.0.113.10:443
protocol=TCP action=allowed

This supports the narrow statement that the firewall allowed traffic matching those values. Further records are needed to explain the user, content or final outcome.

The point to remember

Establish what this firewall could see and record before treating one line as a complete account of the communication.

Reference: IP-099IP Addresses & Networks