# Schedule the full Microsoft Tunnel verbose-log collection window

> What does Microsoft Tunnel Send logs collect, and when must a problem be reproduced?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:43+00:00
- Modified: 2026-09-10T02:08:05+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

What does Microsoft Tunnel Send logs collect, and when must a problem be reproduced?

## Potentially affected

Use this planning check for the Intune-admin-center collection on a Tunnel Gateway server. Confirm the support case or diagnostic purpose and whether the required evidence is server detail or access logging.

## DSE recommendation

Arrange the reproduction window before starting the eight-hour collection.

## Article

## Source facts

Microsoft Tunnel Send logs first uploads the current server logs, then enables verbosity level four for eight hours before uploading a second set. The issue should be reproduced during that verbose interval. The interval cannot be stopped early or extended. Collection finishes by resetting verbosity to zero, even if a different level was previously configured. Access logs named ocserv-access are excluded. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/monitor).

## Applicability

Use this planning check for the Intune-admin-center collection on a Tunnel Gateway server. Confirm the support case or diagnostic purpose and whether the required evidence is server detail or access logging.

## DSE recommendation

Arrange the reproduction window before starting the eight-hour collection. Assign someone to reproduce the approved scenario and record its time, server, and client context. Note any existing custom verbosity so its intended setting can be reviewed afterward. Agree on sensitive-log handling with the support owner, and do not assume the upload includes every log category.

## Verification

Check both upload records and their collection intervals, verbosity, and completion status. Confirm the reproduced event falls inside the verbose set. Afterward, inspect the effective verbosity and restore an approved custom setting only if still required. Treat a missing access-log event as a scope question before repeating the same collection, and avoid leaving verbose logging as the normal operating configuration.

## Official references

[Microsoft Learn: Monitor the Microsoft Tunnel VPN solution for Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/monitor).

## Primary reference

- Name: Monitor the Microsoft Tunnel VPN solution for Microsoft Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/monitor
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Schedule the full Microsoft Tunnel verbose-log collection window,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-493-schedule-the-full-microsoft-tunnel-verbose-log-collection-window/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
