Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is a firewall log?

A firewall log records how one control point handled observed traffic under configured rules. It does not by itself prove an attack, completed connection or data transfer.

Action describes the firewall decision

Entries may contain source and destination, ports, protocol, rule, allow, reject or drop action, interface, session, bytes and time. A block shows traffic reached that control and was not permitted there. An allow shows permission, not acceptance or application outcome. NAT may require mapping internal, public and translated ports.

Join decision to later evidence

Obtain rule and action definitions, firewall position, zone, NAT and whether the entry marks packet, session start or end. Preserve relevant configuration.

Compare endpoint, server, proxy, VPN, DNS and application logs to distinguish attempt, establishment and successful action.

The point to remember

A firewall row proves a configured traffic decision at one point; downstream records prove what happened after it.

Reference: LOG-020Logs, Records & Provider Evidence