Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

How can account, device, session and network events be linked?

Link them by following scoped identifiers through a technically coherent sequence: authentication creates a session, the session acts through an application, and network and endpoint records locate its connections and processes.

Each layer supplies a different part of the chain

Authentication may provide account, session, client and source details. Application events can carry session or request IDs. Endpoint records identify processes and logged-in contexts, while DHCP, VPN, proxy and translation logs map addresses to devices over time.

No field is universal. Addresses can be shared, names duplicated and session IDs unique only within one service.

Use multiple compatible joins where possible: account to session, session to request, request to outcome, and device to contemporaneous network assignment. Check time zones, clock offset and ingestion delay, and consider automation, service identities and remote control.

Document every linking step against preserved source records. The chain should show what the systems connect before any further inference about the person controlling them.

The point to remember

Cross-system attribution depends on several scoped identifiers aligning in the expected technical sequence.

Reference: LOG-135Logs, Records & Provider Evidence