{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window/",
        "slug": "dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window/"
        },
        "title": "Schedule the full Microsoft Tunnel verbose-log collection window",
        "summary": "What does Microsoft Tunnel Send logs collect, and when must a problem be reproduced?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:23:43+00:00",
        "modified_at": "2026-09-10T02:08:05+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 228,
        "potentially_affected": "Use this planning check for the Intune-admin-center collection on a Tunnel Gateway server. Confirm the support case or diagnostic purpose and whether the required evidence is server detail or access logging.",
        "dse_recommendation": "Arrange the reproduction window before starting the eight-hour collection.",
        "primary_source": {
            "name": "Monitor the Microsoft Tunnel VPN solution for Microsoft Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/monitor",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft Tunnel Send logs first uploads the current server logs, then enables verbosity level four for eight hours before uploading a second set. The issue should be reproduced during that verbose interval. The interval cannot be stopped early or extended. Collection finishes by resetting verbosity to zero, even if a different level was previously configured. Access logs named ocserv-access are excluded. <a href=\"https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/monitor\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this planning check for the Intune-admin-center collection on a Tunnel Gateway server. Confirm the support case or diagnostic purpose and whether the required evidence is server detail or access logging.</p>\n<h2>DSE recommendation</h2>\n<p>Arrange the reproduction window before starting the eight-hour collection. Assign someone to reproduce the approved scenario and record its time, server, and client context. Note any existing custom verbosity so its intended setting can be reviewed afterward. Agree on sensitive-log handling with the support owner, and do not assume the upload includes every log category.</p>\n<h2>Verification</h2>\n<p>Check both upload records and their collection intervals, verbosity, and completion status. Confirm the reproduced event falls inside the verbose set. Afterward, inspect the effective verbosity and restore an approved custom setting only if still required. Treat a missing access-log event as a scope question before repeating the same collection, and avoid leaving verbose logging as the normal operating configuration.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/monitor\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Monitor the Microsoft Tunnel VPN solution for Microsoft Intune</a>.</p>",
        "content_text": "Source facts\nMicrosoft Tunnel Send logs first uploads the current server logs, then enables verbosity level four for eight hours before uploading a second set. The issue should be reproduced during that verbose interval. The interval cannot be stopped early or extended. Collection finishes by resetting verbosity to zero, even if a different level was previously configured. Access logs named ocserv-access are excluded. Microsoft Learn.\nApplicability\nUse this planning check for the Intune-admin-center collection on a Tunnel Gateway server. Confirm the support case or diagnostic purpose and whether the required evidence is server detail or access logging.\nDSE recommendation\nArrange the reproduction window before starting the eight-hour collection. Assign someone to reproduce the approved scenario and record its time, server, and client context. Note any existing custom verbosity so its intended setting can be reviewed afterward. Agree on sensitive-log handling with the support owner, and do not assume the upload includes every log category.\nVerification\nCheck both upload records and their collection intervals, verbosity, and completion status. Confirm the reproduced event falls inside the verbose set. Afterward, inspect the effective verbosity and restore an approved custom setting only if still required. Treat a missing access-log event as a scope question before repeating the same collection, and avoid leaving verbose logging as the normal operating configuration.\nOfficial references\nMicrosoft Learn: Monitor the Microsoft Tunnel VPN solution for Microsoft Intune.",
        "content_markdown": "## Source facts\n\nMicrosoft Tunnel Send logs first uploads the current server logs, then enables verbosity level four for eight hours before uploading a second set. The issue should be reproduced during that verbose interval. The interval cannot be stopped early or extended. Collection finishes by resetting verbosity to zero, even if a different level was previously configured. Access logs named ocserv-access are excluded. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/monitor).\n\n## Applicability\n\nUse this planning check for the Intune-admin-center collection on a Tunnel Gateway server. Confirm the support case or diagnostic purpose and whether the required evidence is server detail or access logging.\n\n## DSE recommendation\n\nArrange the reproduction window before starting the eight-hour collection. Assign someone to reproduce the approved scenario and record its time, server, and client context. Note any existing custom verbosity so its intended setting can be reviewed afterward. Agree on sensitive-log handling with the support owner, and do not assume the upload includes every log category.\n\n## Verification\n\nCheck both upload records and their collection intervals, verbosity, and completion status. Confirm the reproduced event falls inside the verbose set. Afterward, inspect the effective verbosity and restore an approved custom setting only if still required. Treat a missing access-log event as a scope question before repeating the same collection, and avoid leaving verbose logging as the normal operating configuration.\n\n## Official references\n\n[Microsoft Learn: Monitor the Microsoft Tunnel VPN solution for Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/monitor)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Schedule the full Microsoft Tunnel verbose-log collection window",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window/",
                "headline": "Schedule the full Microsoft Tunnel verbose-log collection window",
                "description": "What does Microsoft Tunnel Send logs collect, and when must a problem be reproduced?",
                "abstract": "What does Microsoft Tunnel Send logs collect, and when must a problem be reproduced?",
                "articleBody": "Source facts\nMicrosoft Tunnel Send logs first uploads the current server logs, then enables verbosity level four for eight hours before uploading a second set. The issue should be reproduced during that verbose interval. The interval cannot be stopped early or extended. Collection finishes by resetting verbosity to zero, even if a different level was previously configured. Access logs named ocserv-access are excluded. Microsoft Learn.\nApplicability\nUse this planning check for the Intune-admin-center collection on a Tunnel Gateway server. Confirm the support case or diagnostic purpose and whether the required evidence is server detail or access logging.\nDSE recommendation\nArrange the reproduction window before starting the eight-hour collection. Assign someone to reproduce the approved scenario and record its time, server, and client context. Note any existing custom verbosity so its intended setting can be reviewed afterward. Agree on sensitive-log handling with the support owner, and do not assume the upload includes every log category.\nVerification\nCheck both upload records and their collection intervals, verbosity, and completion status. Confirm the reproduced event falls inside the verbose set. Afterward, inspect the effective verbosity and restore an approved custom setting only if still required. Treat a missing access-log event as a scope question before repeating the same collection, and avoid leaving verbose logging as the normal operating configuration.\nOfficial references\nMicrosoft Learn: Monitor the Microsoft Tunnel VPN solution for Microsoft Intune.",
                "datePublished": "2026-09-10T00:23:43+00:00",
                "dateModified": "2026-09-10T02:08:05+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Schedule the full Microsoft Tunnel verbose-log collection window"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 228,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Monitor the Microsoft Tunnel VPN solution for Microsoft Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/monitor"
                }
            }
        ]
    }
}