Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is a web-server access log?

A web-server access log records requests that reached a web service and its recorded responses. It does not automatically prove a person viewed content or completed the action suggested by a path.

Requests can be human or automated

Fields commonly include address, time, method, path, response, bytes, referrer and user agent. Browsers, applications, scripts, crawlers, scanners and prefetching can all generate requests. A response code concerns the server stage, not necessarily a completed business transaction.

Account for intermediaries

Identify the generating server, format, zone and any reverse proxy, load balancer or delivery network that may replace the client address. Preserve session, request and correlation IDs and surrounding requests.

Compare authentication, application, database, proxy and endpoint evidence to establish actor, content delivery and final outcome.

The point to remember

A web access row proves a server request and response; intent, viewing and completed action require corroboration.

Reference: LOG-024Logs, Records & Provider Evidence