Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is a VPN log?

A VPN log records events at a virtual-private-network service or gateway. It may establish an account session and address assignment, but not all later activity or the human behind it.

Session mapping is the core value

Records can include account, start and end, source address, assigned internal address, authentication, endpoint, gateway, bytes and session ID. Coverage and retention vary. Shared endpoints, compromise, remote access and chained services affect attribution.

Reused assigned addresses can mislead unless account, session and time align precisely.

Join both sides of the tunnel

Identify operator and service type, fields, zone, authentication and assignment history. Preserve promptly and correlate identity-provider, endpoint, firewall, application and provider records.

Do not infer browsing content from connection metadata or physical location from the incoming address without further evidence.

The point to remember

Use VPN records to map a time-specific account session to assigned network activity, then establish user and content separately.

Reference: LOG-023Logs, Records & Provider Evidence