A door access log where an out-of-hours entry and a denied attempt at a cabinet are the two rows worth reviewing

Access Logging

Back to Data Center Management · Badge or Biometric Access · Visitor and Vendor Tracking · Cage or Rack-Level Restriction · Service Offerings

Access logging is a record of who entered and when, reviewable after the fact if something needs investigating. Most sites have the first half. The control is the second half, and it is the half that gets skipped.

A log nobody reads is not a control. It is evidence, available to whoever eventually goes looking, which is useful but entirely retrospective. What turns it into a control is somebody looking at it on a schedule, before anyone has a reason to.

1. What a Row Should Contain

2. The Denials Are the Interesting Part

Granted entries are the bulk of the log and mostly tell you that the day happened. The rows worth a human's attention are the exceptions, which is what the illustration above is pointing at:

Most of these can be alerted on rather than reviewed by eye, which is what makes the review sustainable. The monthly read-through then covers the pattern rather than the volume.

3. Retention Longer Than Discovery

The question a log answers is always asked later than the event. Set retention against how long it realistically takes to find out something happened — not against how long the system happens to keep by default, which is frequently thirty days and occasionally a fortnight.

4. The People in the Log Must Not Control the Log

An audit trail administered by the people it records is not an audit trail. This is not an accusation of anyone; it is simply the property that makes the record worth anything.

5. One Log Rarely Answers the Question

"Who was in the room when that server was unplugged" is not answered by door records alone. It is answered by lining several records up on a common timeline:

Source What it adds
Door and cabinet accessWho could have been there, and when they arrived
CCTVHow many people actually went through, which the badge cannot tell you
Visitor registerAnyone present without a credential of their own — see visitor and vendor tracking
Change and ticket recordsWhether the visit was supposed to happen
Equipment and monitoringWhat changed, and at what second. See root cause diagnosis

Which is the practical reason for the synchronised clock in section 1. Timelines that are four minutes apart are reconstructed by argument rather than by evidence.

6. In a Shared Facility, Half the Log Is Someone Else's

In colocation, the provider holds the records for the building and the hall; you hold the records for your own cage and cabinets, if you installed anything to produce them. Two things to settle in the contract rather than during an incident:

How We Approach It

  1. Find out what is recorded today, where it lives, and how long it genuinely survives — tested, not quoted from a policy.
  2. Fix the fields, so a row names a person and a door and carries a synchronised timestamp.
  3. Export to somewhere independent, with administrative actions logged too.
  4. Define the exceptions worth alerting on, so the review is about patterns rather than volume.
  5. Establish the review: who, how often, what they sign, and what happens to what they find.
  6. Settle the colocation records you are entitled to, and close the gap at the cage layer.

What You Get

The test is whether you could answer, next March, who was in the room at 02:17 last Tuesday — and whether anyone would have noticed at the time that someone was.