Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is a network log?

A network log records communication metadata observed at one device or monitoring point. It does not recreate everything a user did or necessarily expose encrypted content.

Observation point defines visibility

Routers, switches, firewalls, wireless controllers, load balancers and sensors may record addresses, ports, protocol, direction, action, volume, interface and time. NAT, proxies, VPNs and cloud routing can change visible endpoints, while updates, synchronisation and automation can generate traffic.

Reconstruct route and outcome

Establish where the record was created, what it could see, address scope, translations, zone and whether it holds packets, flow or connection metadata. Preserve configuration and related events.

Correlate DHCP, VPN, authentication, endpoint, application and provider records. A connection attempt does not prove successful exchange or identify the user.

The point to remember

Interpret network records from their observation point and join other systems to establish endpoint, outcome and user.

Reference: LOG-019Logs, Records & Provider Evidence