§ Guide

Website Web Server And Application Logs

This guide, 'Website, Web Server and Application Logs', is for UK lawyers, in-house counsel, and investigators.

Ref · E-D · 2026 · §LIBClass · ConfidentialJuris · England & WalesStatus · Active

Guide · 17 pages · 21 min read · Published 2026-08-30

This guide, 'Website, Web Server and Application Logs', is for UK lawyers, in-house counsel, and investigators. It addresses reconstructing user journeys, proving page state, and attribution on websites. The guide covers the log estate, including servers, applications, CDNs, and analytics, and discusses retention, collection, and preservation. It provides worked examples, common mistakes, technical limitations, and questions to ask. Key topics include sessions, clicks, transactions, and proving what a site showed and when. Attribution methods, such as IP, account, device, and human, are also detailed. It is essential for understanding how layered logs reconstruct user actions and how page-state proof and attribution determine their meaning.

Read this guide on your phone, browse guides by topic or go back to the full PDF library.

§ Credit and source

Published by Computer Forensics Lab on 2026-08-30. Original material of the practice, free to read, cite and download. The authority behind this subject is ICO guide to the UK GDPR, which you should read alongside this guide. See every guide's author and source.

§ Full text of Website Web Server And Application Logs

Download the PDF

Prefer a PDF that matches this page exactly? Download the current text as a PDF, generated from the wording shown here, including any later corrections.

Page 1

WEB & APPLICATIONLOGS · A GUIDE FOR UK LAWYERS Website, Web Server and Application Logs Request Trails, User Journeys and Proving What Happened on a Website COMPUTER FORENSICS LAB

§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM USER-JOURNEY RECONSTRUCTION CPR PART 35 EXPERT REPORT S FULL CHAIN-OF-CUSTODY DOCUMENTATION

§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: the site remembers every request 03 The log estate: servers, applications, CDNs and analytics 04 Reconstructing journeys: sessions, clicks and transactions 05 Proving page state: what the site showed and when 06 Attribution: IP, account, device, human 07 Retention, collection and the preservation race 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist

§ 01 · ORIENTATION Executive summary THE HEADLINE POINT: LAYEREDLOGSRECONSTRUCTWHATAUSERDID; PAGE - STATE PROOFANDATTRIBUTIONDECIDEWHATITMEANS

§ 02 · FIRST PRINCIPLES The problem in plain English: the site remembers every request

§ 03 · THEESTATE The log estate: servers, applications, CDNs and analytics

Page 2

§ 04 · THEJOURNEY Reconstructing journeys: sessions, clicks and transactions

§ 05 · THESCREEN Proving page state: what the site showed and when

§ 06 · WHO Attribution: IP, account, device, human

§ 07 · BEFOREROTATION Retention, collection and the preservation race

§ 08 · THEWIDERMAP Source architecture: where else the evidence lives EVIDENCE BROWSER / SERVER WAF DATABASE IDENTIT Y RECOVERABLE USER'S DEVICE

§ 09 · IN THE WILD Worked examples EXAMPLE1 · THESURCHARGETHECHECKOUTNEVERSERVED EXAMPLE2 · THEREVIEWCAMPAIGNWITHONEFINGERPRINT EXAMPLE3 · THETAKEOVERDEFENCE, TESTEDANDUPHELD

Page 3

§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations

§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent Ask your e Discovery / forensic provider SUGGESTED WORDING · WEB - LOGLIMBFORTHEPRESER VAT I ON LETTER

§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The web-log checklist Red flags When to involve a digital forensic expert

§ 13 · COMMON QUESTIONS Frequently asked questions How long do websites keep their logs? Can logs prove someone read the terms and conditions? We only have an IP address for the wrongdoer. Is that enough? The defendant says their account was hacked. Now what? Is a Wayback Machine capture admissible to show what a page said? Can we get the other side's server logs in disclosure?

§ 14 · REFERENCE Glossary CDN CGNAT WAF Sources and authoritative references DISCLAIMER

§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY

§ Common questions

Frequently asked questions

How long do websites keep their logs?
By default, briefly: server rotations of days to weeks, platform and CDN retention per plan, analytics per configuration: and almost never with litigation in mind. Treat every web matter as a guide 77-style race: census the layers, ask each one's retention, and send the §11 letter inside the shortest answer.
Can logs prove someone read the terms and conditions?
They prove service: the terms URL requested and returned 200 in the session, the checkbox posted, the version live that day (from the §5 history): which is what online-contract law generally needs: reasonable notice and incorporation, not telepathy. What no log proves is reading: plead the served-and-accepted sequence, and let Example 1 remind you to verify the serving before relying on it.
We only have an IP address for the wrongdoer. Is that enough?
It is a start: an IP plus a precise UTC timestamp supports subscriber disclosure from the ISP (Norwich Pharmacal being the usual route), and the account, device and fingerprint layers usually thicken the ladder before and after: Example 2's fourteen accounts fell to exactly that stack. An IP alone, pleaded as a person, is the mistake; an IP used as the first rung is the method.
The defendant says their account was hacked. Now what?
Test it: the take over defence has a signature either way: login geography and device history, resets and recovery-detail changes, the platform's own anomaly flags, and the counterpart-device question (was the accused's machine active, and did it touch the site?). Example 3 shows the defence surviving honest exam in at i on; fabricated versions rarely do, because take over s leave their own trail and its absence is loud.
Is a Wayback Machine capture admissible to show what a page said?
Routinely received, sensibly weighed: it is a dated third-party snapshot, strong for static public pages at its capture moments, silent between them and for personalised content. Use it as one voice beside deployment history, CMS records and the counterpart browser: the §5 chorus: rather than as the soloist.
Can we get the other side's server logs in disclosure?
Yes, where relevant and proportionate: they are documents within control like any other, and PD 57AD's models reach them: the craft is asking per §11: named layers, defined sessions and periods, raw formats, retention stated: so the request is cheap to comply with and expensive to resist. Expect the proportionality conversation, and win it by narrowness. cflab. u k · e-disc ove r y. u k ©2026 Computer Forensics Lab Ltd ·cflab.uk ·e-discovery.uk ·info@cflab.uk ·+44 (0)20 7164 6915 Page 15 of 17
§ Related documents
Instruct the practice

Bring us in early. Defensibility is built, not retrofitted.

Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.

WhatsApp