How a small Russian software company turned proxy logs into office visibility — and why that idea never went away.

The short version

  • Before dashboards, before SIEM, before cloud-native observability, there was a simpler problem: the company had an internet connection, people were using it, and nobody knew for what.
  • Internet Access Monitor was the headline, but Red Line Software built two companion products on the same log-parsing philosophy.
  • For its era, this was exactly the right approach.

01From Log Files to the Boss's Desk

Before dashboards, before SIEM, before cloud-native observability, there was a simpler problem: the company had an internet connection, people were using it, and nobody knew for what. Proxy servers — Squid, WinGate, Microsoft ISA — were already writing detailed access logs for every HTTP request that passed through them. The data was there. It just sat in text files nobody read.

Red Line Software, a Russian software developer active through the 2000s and early 2010s, built its product line around the insight that those logs were a gold mine waiting to be parsed. Their flagship, Internet Access Monitor, took the access logs produced by the most common proxy servers of the era and turned them into readable, per-user reports: which websites each employee visited, how much data they transferred, how their usage broke down over the working day. No network taps, no agents installed on desktops, nothing touching the endpoints at all. The tool was agentless by design — it simply read what the proxy was already writing.

The supported list read like a roll call of early-2000s gateway software: Squid, WinGate, Kerio WinRoute, Microsoft ISA Server, UserGate, Traffic Inspector, and several others. Each flavour of proxy wrote its logs in a slightly different format; Internet Access Monitor handled the translation, producing a unified view regardless of which gateway sat at the network edge. For a small-office IT administrator managing a shared ADSL line, that was genuinely useful.

Screenshot or period-accurate UI mockup of a proxy-log usage report
Period-accurate proxy-log usage report summarising per-user web activity

02The Trio: Proxy, Mail, Print

Internet Access Monitor was the headline, but Red Line Software built two companion products on the same log-parsing philosophy.

Mail Access Monitor applied the same approach to mail-server logs. Where the internet monitor told you which websites people were visiting, the mail tool told you how many messages were sent and received, by whom, to which domains, and how much traffic each mailbox generated. Again, no agents, no content inspection — just the metadata that mail servers had always recorded.

Printer Activity Monitor extended the idea to print accounting. Print servers log every job: who sent it, when, how many pages, which printer. Printer Activity Monitor parsed those records and reported on print usage across the organisation — a genuinely unglamorous but commercially useful problem, particularly in offices that billed print costs back to departments or clients.

Together the three products formed a coherent suite: internet usage, mail traffic, and print accounting, each built on the same architectural conviction that the infrastructure you already had was already recording enough data to answer the questions managers were actually asking.

03Why It Mattered — and Why It Faded

For its era, this was exactly the right approach. Proxy logs were the dominant visibility surface for internet traffic in an age when most workplace browsing was unencrypted HTTP, proxy servers were the standard gateway pattern, and the internet connection itself was a scarce, shared, genuinely rationed resource. Knowing that one user had downloaded 2 GB over the week — when the office's total monthly allowance was 10 GB — was actionable information. Internet Access Monitor made that information accessible without requiring IT to write custom log-parsing scripts.

The product's decline was architectural, not philosophical. As HTTPS became the default for nearly all web traffic, plain proxy logs revealed progressively less — a destination hostname, not a full URL; a byte count, not a page title. As internet bandwidth became cheap and abundant, the rationing problem receded. And as network monitoring matured into flow-based analysis, DNS-level visibility, and cloud-delivered CASB platforms, the proxy-log niche narrowed. The problem Internet Access Monitor solved so cleanly for 2005 had been reshaped by 2015 into something that needed different tools.

Side-by-side icon/logo trio representing internet, mail, and print
Internet, email, and print icons representing the three channels Internet Access Monitor tracked

04Carrying the Name Forward

This site — Internet Access Monitor — is an independent publication, not affiliated with Red Line Software and not a continuation of their product. We carry the name because it describes exactly what this guide is about: monitoring how your network accesses the internet. The original software is a matter of record, genuinely useful in its time, and worth understanding as context for how the field evolved.

The core question Red Line Software asked hasn't changed. You have a network, users are connecting to services, and you want to know what's actually happening. The logs, flows, and DNS records of 2026 tell you more than any proxy log ever could — if you know how to read them. That's what this site is for.

05Timeline

  1. Early 2000sHTTP-dominant web; proxy logs capture full URLs; Internet Access Monitor fills a real gap
  2. Mid-2000sproduct suite complete: Internet Access Monitor, Mail Access Monitor, Printer Activity Monitor
  3. ~2010–2015HTTPS adoption accelerates; proxy-log visibility degrades; bandwidth prices fall
  4. 2015 onwardflow analysis, DNS visibility, CASB replace the proxy-log niche
Split image comparing an old proxy-log text file to a modern flow and DNS dashboard
Raw proxy-log text file on the left, a modern flow and DNS dashboard on the right

06Tools & references mentioned