Skip to content
LOG-023 Logs, Records & Provider Evidence

What is a VPN log?

A VPN log records activity associated with a virtual private network service or gateway.

In an organisational setting, that may include remote workers connecting into an internal network. In a commercial service, it may record connections through shared VPN infrastructure.

Avoid this assumption: That a VPN log automatically reveals either everything the user did or the true location and identity of the person behind the connection. It does neither by default.

A VPN log may record account identifiers, connection start and end times, source IP address, assigned internal address, authentication method, device information, gateway, data volume and session ID. This can help establish that an account or device created a VPN session and which network address was assigned.

But available fields vary greatly. Some services keep detailed connection records; others retain limited operational data. A log showing a source IP identifies a connection used to reach the VPN, not necessarily the person controlling it. Shared devices, compromised accounts, remote access and chained services may complicate attribution.

An assigned VPN address can be particularly important when correlating internal network activity. Investigators must match the correct user, session, address and time window. Reused addresses and overlapping sessions can produce misleading conclusions if correlation is imprecise.

Ask who operated the VPN, what type of service it was and which records existed at the relevant time. Obtain field definitions, time-zone information, authentication logs, session identifiers and address-assignment records. Preserve source records promptly because retention may be limited.

Correlate VPN evidence with identity-provider, endpoint, firewall, application and provider records. Do not infer browsing content from a connection log unless the service actually recorded it.

Operational takeaway

A VPN log may establish that an account or device used a particular VPN session, but coverage, retention, address assignment and attribution must be proved from the actual records.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.