The Evidential Value of Server and Network Logs in Software Audits
The Evidential Value of Server and Network Logs in Software Audits
In software licensing disputes, one of the most critical questions is no longer simply "does the company have unlicensed software?". The real debate focuses on how to prove this use, which technical data will be considered legally valid evidence in court , and which records alone will not suffice . Especially in software audits conducted in corporate companies, server logs, network traffic records, licensing server data, Active Directory records, VPN session information, firewall logs, and user access reports form the backbone of the case. In Turkish law, electronic data is not, in principle, excluded from the evidentiary system; on the contrary, the Code of Civil Procedure explicitly considers electronic data as "documents". However, not all electronic data has the same weight; criteria such as lawful acquisition, integrity, immutability, source accuracy, and suitability for expert review directly affect the weight of the evidence.
Therefore, the topic of "evidentiary value of server and network logs" is not merely a matter of technical examination; it is a multi-layered legal issue requiring a comprehensive understanding of the Law on Intellectual and Artistic Works, the Code of Civil Procedure, the Code of Criminal Procedure, the Electronic Signature Law, and the Law on the Protection of Personal Data. Computer programs are protected as works under the Law on Intellectual and Artistic Works; a definition of a computer program has been established, computer programs expressed in all forms are considered works, and the acts of installing, viewing, running, transmitting, and storing the program are evaluated within the scope of the right of reproduction. Therefore, log records regarding which server, which user account, on what date, how many times, and under what license a software program was run within a company network often become central to any infringement discussion.
Why are server and network logs so important?
In software audits, physical copies are often not decisive. Especially with subscription-based, cloud-supported, license-server-based, or centrally distributed software, infringement claims are often identified not from the installation file on the device itself, but authentication, login, license checkout, simultaneous users, IP access, server connection , and application calls . For example, if a company has increased the actual usage of CAD software with ten-user licenses to forty users, this can sometimes be demonstrated much more strongly through license server records, domain logs, and network access tables than from a desktop screenshot. Under the Turkish Copyright Law, the fact that computer programs are considered works and that their installation and execution fall within the financial rights of the rights holder makes these records legally significant.
In other words, server and network logs are not merely “technical ancillary data.” They can indicate whether the software was actually used, whether the use was isolated or systematic within the company organization, whether the use shifted from a limited model such as a trial or training license to commercial use, and whether the unauthorized installation was due to user error or corporate policy. Therefore, well-structured log records can sometimes be more powerful than witness testimony, and sometimes even form the backbone of an expert report. The fact that the Turkish Code of Civil Procedure considers “data in electronic form” as documents already forms the basis for considering such technical data in legal proceedings.
The fundamental grounds for accepting electronic logs as evidence in Turkish law
In legal proceedings, the first and most important basis is Article 199 of the Code of Civil Procedure. According to this provision, written or printed texts, photographs, films, video or audio recordings, and data in electronic form and similar information carriers suitable for proving the facts in dispute are considered "documents." This definition is extremely broad and can encompass server logs, network access records, license server reports, system export files, email header records, and similar electronic data. However, the fact that these data are considered documents does not automatically mean that each of them is strong and indisputable evidence; it only shows that the legal system does not exclude them from the outset.
Next to this, Article 189 of the Turkish Code of Civil Procedure sets a separate threshold: evidence obtained illegallycannot be considered by the court in proving a fact. Therefore, a company or rights holder illegally accessing the opposing party's system under the pretext of software auditing and obtaining records; using excessive, unannounced, and unsubstantiated monitoring mechanisms; or conducting the data collection process outside legal limits can render the evidence disputed. The method by which electronic logs are obtained is as important as their power in court. In Turkish procedural law, the legality of the acquisition crucial as its technical content.
Articles 219 and 220 of the Turkish Code of Civil Procedure are two crucial provisions in software audits. Parties are obligated to submit to the court all documents in their possession that they or the opposing party rely upon as evidence. Electronic documents must also be submitted electronically in a format suitable for review upon request, provided they are printed out. If the court deems the requested document essential for proof, it may set a definite deadline; if the party fails to submit the document without providing an acceptable excuse, the court may accept the other party's statement regarding the document's content. These provisions have significant practical implications in software licensing cases: a company possessing logs may not always be deemed sufficiently reliant on the defense of "we cannot provide them due to systemic issues.".
A stronger category of electronic proof emerges with data bearing secure electronic signatures. According to Article 205 of the Code of Civil Procedure (HMK) , electronic data created with a secure electronic signature in accordance with the procedure has the force of a promissory note, and the judge shall, ex officio, examine whether the electronically signed document presented as evidence was created with a secure electronic signature. Article 210 of the HMK regulates expert examination in case of denial of data bearing a secure electronic signature. In parallel, the Electronic Signature Law No. 5070 recognizes that a secure electronic signature has the same legal effect as a handwritten signature; that a secure electronic signature is a structure dependent on the signatory, created with a tool under their control, making them identifiable, and capable of detecting whether any subsequent changes have been made to the signed data. Therefore, log packets supported by timestamps and secure electronic signatures can carry much higher evidentiary weight than ordinary screenshots.
The material significance of server logs from the perspective of the Law on Intellectual and Artistic Works
The importance of logs in software audits isn't solely due to the broad definition of "document" in the Turkish Code of Civil Procedure (HMK). The main point is that the Turkish Copyright Law (FSEK) protects computer programs as works of art and extends actions related to their use to the realm of financial rights infringement. Computer programs are defined in FSEK Article 1/B, considered scientific and literary works in Article 2, and Article 22 states that the right of reproduction also encompasses the acts of installing, viewing, running, transmitting, and storing the computer program. Therefore, in a license audit, "how many devices the program is installed on in the company system" is as important as "which user ran it and on what dates." Server logs gain significance precisely at this point.
Article 68 of the Turkish Copyright Law (FSEK) allows copyright holders to claim up to three times the price they would have requested in the case of a contract or the market value, if their work is processed, reproduced, distributed, or made available to the public without their written permission. Article 71 of the FSEK stipulates imprisonment for one to five years or a judicial fine for anyone who, without the written permission of the copyright holder, processes, reproduces, distributes, makes available to the public, offers for sale, purchases for commercial purposes, imports or exports, possesses or stores a work other than for personal use, infringes on moral, financial, or related rights. Because of these provisions, log records are important not only in private law compensation cases but also in criminal proceedings. This is because the same record can serve to show both actual use and storage or systematic reproduction for commercial purposes.
The importance of digital records in criminal investigations
In some cases, the use of unlicensed software constitutes a crime under Article 71 of the Law on Intellectual and Artistic Works (FSEK), bringing the criminal procedural aspect into play. Article 134 of the Code of Criminal Procedure (CMK) permits, by court order, searching computers and computer programs, copying and decrypting records if there is no other way to obtain evidence. If the password cannot be decrypted or the hidden information cannot be accessed, the devices can be seized; all data in the system is backed up, and if requested, a copy of this backup is given to the suspect or their lawyer. This regulation is important in criminal investigations for the preservation of the integrity of digital evidence and its subsequent auditability. Therefore, in cases extending from software audits to criminal files, how server records are collected and how the forensic computing chain is established becomes critical.
The conclusion is this: The same log record can be considered "evidence" in a civil lawsuit, but in a criminal case it can be the subject of forensic computing material and expert examination. However, the common problem remains the same in both areas: Is the source of the records clear, is the collection method lawful, is the record susceptible to subsequent alteration, is the system clock reliable, and is the platform on which the data was generated identified? A log set that the court does not trust may be legally weak, even if it is technically rich.
Which logs constitute stronger evidence?
Not all logs have the same probative value. In practice, the strongest records are usually those that corroborate each other across multiple layers. For example, if simultaneous usage for the same user account appears in the license server log, it's possible to support this with Active Directory session logs, VPN connection logs, and firewall traffic. This creates a data chain that doesn't rely on a single program output, but rather comes from different systems and corroborates each other. This multi-layered structure weakens the expert's criticism of "assumptions dependent on a single source." According to the principle of freely evaluating data that constitutes documentation under the Code of Civil Procedure, the judge will find this holistic picture more convincing.
On the other hand, methods such as timestamps, secure electronic signatures, change logs, hash verification, and read-only archiving also increase the evidentiary value. Although the word "hash" is not mentioned in the law, considering that Law No. 5070 requires that changes in secure electronic signatures be detectable, that timestamps are defined for the purpose of determining the time when electronic data was produced or recorded, and that Article 205 of the Code of Civil Procedure recognizes data with a secure electronic signature as a promissory note, whose integrity is preserved and where subsequent tampering is detectable constitute much stronger evidence. Furthermore, the emphasis in Law No. 5651 on the protection of the accuracy, integrity, and confidentiality of traffic information for location and access providers shows that Turkish law is concerned not only with the mere existence of digital records but also with their reliability. Ordinary company internal networks may not be directly subject to the entire retention regime of Law No. 5651; because the law is primarily aimed at content, location, access, and collective use providers. However, the integrity and confidentiality criteria still point to a standard that should be emulated in software audits.
The main problems that weaken the evidentiary value
The biggest problem in practice is that companies believe they are keeping logs but do not keep logs suitable for court proceedings. Logs that are merely screenshots, of unknown origin, with unclear export server details, poor time synchronization, inability to match usernames with real people, and lack separation between test and live environments, pose serious vulnerabilities. Such data may be considered "supporting evidence" in an expert report; however, it may be insufficient on its own to definitively prove a breach. Especially in systems where individuals with administrative privileges can later alter logs, the weight of the evidence decreases if there is no guarantee of immutability. The fact that the Code of Civil Procedure accepts such documents does not eliminate the debates surrounding forgery and denial.
The second major issue is legal compliance. Companies sometimes assume they can monitor all digital activities of employees without limit under the pretext of "conducting audits." However, according to the Personal Data Protection Law (KVKK), the person whose personal data is being processed must be informed about who is processing the data, for what purpose, on what legal grounds, and to whom it may be transferred. At the same time, the data controller is obliged to prevent the unlawful processing and access of personal data, to ensure its preservation, and to take the necessary technical and administrative measures. Therefore, logging practices that are excessive, unclear in purpose, conducted without proper notification, or that collect excessive data may lead to future disputes under Article 189 of the Code of Civil Procedure (HMK). Especially in employee monitoring systems, "why data is collected" is as important as "how much data is collected.".
Why is evidence gathering important in software audits?
The weakest point of server and network logs is that they are often not permanent. Some logs automatically return after seven days, some after thirty, some after ninety days; the default retention period is even shorter in some cloud infrastructures. Therefore, it is possible for evidence to be lost before the dispute even reaches the litigation stage. This is of evidence determination , as stipulated in Article 400 and subsequent articles of the Code of Civil Procedure, comes into play. Parties may request on-site inspection, expert examination, or similar procedures to determine a fact they will present in a pending or future lawsuit; a legal interest is deemed to exist if there is a possibility that the evidence will be lost or its presentation will be significantly hampered if it is not determined immediately. This institution is extremely functional in software audit disputes.
In practice, this means that the rights holder can request a swift expert review from the court if there is a possibility of the logs being deleted; the company, on the other hand, can record early on, through evidence gathering, what the system actually showed, which license model was active, and that the alleged user density is technically incorrect, in response to the allegations against it. Evidence gathering is not only a tool for attack; it is also a powerful mechanism for defense. Especially in complex technical situations such as license server errors, test users, virtual machine copies, disabled clients, and historical log corruptions, early detection is far more effective than a delayed defense.
What should companies pay attention to when keeping logs?
The first rule is not to start logging only when a lawsuit arises, but to make it a part of normal corporate governance. The company must predetermine which software it uses and under what licensing model, which server hosts the licensing server, user account-machine mapping, central time synchronization, log retention period, authorization matrix, and external access. Logs must not only be kept, but also regularly verified and reported. Otherwise, the data presented to the court remains a "raw mass," and its technical meaning may not be clarified even by an expert. Article 219 of the Code of Civil Procedure, which mandates the submission of electronic documents in a format suitable for examination, already necessitates regular, readable, and verifiable record management.
The second rule is not to disregard the personal data aspect. Username, IP address, session date, device information, access pattern, and sometimes location data can all be considered personal data. According to the KVKK (Personal Data Protection Law), the obligation to inform continues in all data processing activities that require explicit consent or are based on other processing conditions. The data controller is obliged to take the necessary technical and administrative measures for data security, conduct or have audits conducted, and inform the Board and the relevant person in case of a breach. Therefore, internal logging policies, information security policies, and the KVKK disclosure text should not be separate but rather compatible parts of each other.
The third rule is to consider the format in which logs will be presented to the court in advance. Instead of relying solely on screenshots in a case, a complete set of documents should be prepared, including an exported log file, a descriptive technical report, a timestamp if necessary, a secure electronic signature if possible, an authorized person's statement, and a short technical diagram showing the log architecture. This is because evidentiary value often lies not in a single file, but in the entire presentation set that makes the file understandable. Since data with a secure electronic signature has the force of a promissory note, bringing critical records closer to this standard can provide a significant advantage for the company.
Conclusion
In Turkish law, server and network logs have extremely high evidentiary value in software audits; however, this power is not automatic. Electronic data is considered a document under the Code of Civil Procedure (HMK). Those with secure electronic signatures can go even further and acquire the force of a promissory note. Since computer programs are protected as works under the Law on Intellectual and Artistic Works (FSEK), log records play a central role in proving actions such as the installation, execution, transmission, and storage of the software. In disputes that reach the criminal dimension, Article 134 of the Code of Criminal Procedure (CMK) establishes a special procedure for searching, copying, and backing up digital materials. On the other hand, the Personal Data Protection Law (KVKK) permits not the unlimited and aimless collection of these records, but their processing in an informed, secure, and proportionate manner.
Therefore, the correct question is not "Are there logs?". The correct question is: Were the logs legally maintained, is their source clear, is their integrity preserved, are they corroborated by other records, and are they suitable for court and expert examination? If strong answers can be given to these questions, server and network logs become one of the most effective pieces of evidence in software license audits. If not, the same logs, even if technically existing, remain legally weak. In short, the power of evidence in software audits lies not only in the data itself, but in the legal architecture .
Frequently Asked Questions
Do server logs alone prove the use of unlicensed software?
Not always. The Code of Civil Procedure considers electronic data as evidence; however, the strength of the evidence depends on its source, integrity, verifiability, and consistency with other records. Instead of raw logs alone, license server records, user account data, and access logs together form a stronger picture.
Can a screenshot be used as evidence?
Yes, it can; however, it is often limited evidence. If it's unclear from which system, on what date, by whom, and how the screenshot was taken, its probative value decreases. It is more reliable to support the electronic data with system exports, minutes, and expert examination.
Is keeping logs of company employees illegal?
Absolutely not; however, the obligations of informing, limiting the purpose, proportionality, and data security under the Personal Data Protection Law must be observed. Furthermore, evidence obtained illegally cannot be considered under Article 189 of the Code of Civil Procedure.
Does a secure electronic signature strengthen legal records?
Yes. According to Article 205 of the Turkish Code of Civil Procedure, electronic data created with a properly secure electronic signature has the force of a promissory note. Law No. 5070 also recognizes that a secure electronic signature has the same legal effect as a handwritten signature.
What can be done about the logs before a lawsuit is filed?
According to Article 400 and subsequent articles of the Code of Civil Procedure, an expert examination can be requested to determine the evidence. Early expert examination is particularly important if there is a risk of the logs being deleted or overwritten.