Skip to content
LOG-041 Logs, Records & Provider Evidence

What is the difference between a source event and a dashboard entry?

A source event is the record created by the original system. A dashboard entry is the way another tool chooses to display that record.

The dashboard may make the event easier to understand, but it is not necessarily a direct copy.

Avoid this assumption: That the dashboard entry contains the exact wording, fields and meaning of the source event. It may not.

A dashboard may rename technical fields, convert timestamps, add user details, assign severity or combine related records. It may hide empty fields, suppress duplicates or display only the information considered useful to the product.

One dashboard row may represent one source event. It may also represent several events grouped into an alert or incident. Conversely, one source event may appear in several dashboard views.

The dashboard can therefore be useful for identifying relevant activity and understanding the system’s current interpretation. But it may also reflect later enrichment, updated rules or changed user-directory information.

Investigators should establish which source produced the event and which platform displayed it. Ask whether the entry is raw, parsed, normalised, enriched, correlated or summarised. Obtain the source event, field mapping and linked identifiers where available.

Check whether the dashboard time is event time, ingestion time or display time. Record any filters, search criteria and time-zone settings used.

Screenshots may be useful for showing what an investigator saw, but they should not replace preservation of the underlying records where those records are obtainable.

Operational takeaway

A dashboard entry is a presentation of source data shaped by parsing, mapping, enrichment and display rules, so significant conclusions should be checked against the underlying event.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.