Evidence
Tailscale logs: decision trails, successful-connection metadata and explicit boundaries.
Different log sources answer different questions. Configuration audit logs show control-plane changes. Network flow logs describe metadata for successful tailnet connections, not traffic content or a complete record of denied attempts. SSH recording applies only to separately configured Tailscale SSH sessions.
Log sources
Select the source based on what must be evidenced.
Logging requirements are defined before delivery. Availability, retention, export and content depend on the Tailscale plan, client telemetry and implementation settings. These sources are not by themselves an IDS, SIEM or tamper-proof evidence store.
Configuration audit logs
- control-plane events and changes
- all plans, enabled by default, 90-day history
- policy changes include the old-to-new diff
Network flow logs
- metadata for successful connections between nodes
- no packet content or complete denied-attempt history
- Premium/Enterprise, endpoint telemetry and 30-day history
Log streaming and SSH
- log export on Premium/Enterprise plans
- beta SSH recording: Personal/Enterprise, separate recorder, terminal output only
- the customer manages ingestion, integrity, retention and access
Evidence chain
A log alone does not prove control design or operation.
- The business decision explains why access was granted.
- The policy diff shows the technical change.
- Positive and negative tests demonstrate intended policy behaviour.
- The audit log shows the control-plane event.
- A flow log can show successful-connection metadata, subject to endpoint reporting, but not traffic content or every denied attempt.
Enabling export does not create a SIEM process
The implementation defines the receiving system, schema, integrity controls, retention, permissions, time synchronisation, alert rules, owner and failure handling. Denied attempts may require local client, host-firewall, egress-control or gateway logs.
AIM model
Logging is tied to the use case and responsibility.
Advice defines the events to evidence, the plan and retention requirements. Integrate enables the sources and implements the agreed export. Manage monitors settings, exceptions and reporting during the agreed Finnish business-hours coverage; monitoring, alerting and incident response are not implied unless explicitly contracted.