--- type: concept tags: [parking, security, access-control, integrity] sources: [parking-system-architecture] updated: 2026-06-14 --- # Event-Log Ingestion (making the UHPPOTE log trustworthy) The host-side discipline that turns the [[uhppote-controller]]'s log — undermined by the [[uhppote-udp-protocol]] — into a solid detection/audit layer. (See [[parking-system-architecture]] §6.) - **Track your own last-ingested index on the host.** Do **not** rely on the controller's current-index pointer — it's user-managed and settable by anyone (`set-event-index`). - Walk **absolute** indices with `get-event `. Treat three things as **alarms**: 1. a **gap** in the sequence, 2. an **"event has been overwritten" error** (you fell behind — data loss), 3. any **door-open event the host never requested**. - Use `set-listener` **auto-push** for low latency, but **always reconcile by index** (UDP pushes can drop). - **Size polling cadence** against the busiest lane's event rate so unread events never roll off. - **Land every event** in the host's signed [[append-only-event-chain]]. Net result: **tamper-evident, behind [[network-isolation]]** — a solid detection layer, but not tamper-proof. Prevention requires the [[esp32-custom-controller]].