Skip to content
LOG-135 Logs, Records & Provider Evidence

How can account, device, session and network events be linked?

Account, device, session and network events can be linked by identifying shared technical identifiers and checking that the sequence is consistent across the systems involved.

No single field should be expected to do all the work.

Avoid the dangerous assumption

The dangerous assumption is that the same username or IP address is enough to prove every record belongs to one person and one session.

It is not.

Start with the authentication event. Identify the account, session ID, device information, source address, application and timestamp. Then look for application or audit events carrying the same session, request or correlation identifiers.

Network records may link the device through an internal address, VPN assignment, DHCP lease or translated connection. Endpoint records may identify the process and logged-in account on the device.

Investigators should map each identifier to its scope. A session ID may be unique only within one application. An IP address may be shared. A device name may change or be duplicated.

Use several compatible links where possible: account plus session, session plus device, device plus network assignment, and request ID plus application outcome.

Check time zones, clock offset and ingestion delay before rejecting a possible match. Also check whether the activity could be automated, remotely controlled or performed through a service account.

Preserve the source records and document the linking steps. Avoid replacing the evidence chain with a single conclusion such as “the user did it”.

Operational takeaway

Cross-system linking is strongest when account, session, device, network and request evidence align in a technically coherent sequence, with each identifier’s scope and limitations made explicit.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.