What is an event?¶
An event is an activity or condition that a system recognises and may process or record. It can result from a person, software, a scheduled task, a device or the system itself.
Systems define event boundaries¶
A login, file access, process start, connection, permission change or error may qualify. One action can generate request, authentication, token and session events across several systems, while one summary event can group repeated activity. Status may describe start, acceptance, failure or completion.
Read the generating condition¶
Identify source, event code, field definitions and the condition that causes generation. Preserve preceding, following and duplicate records and stable account, device, session, process or request identifiers.
An event label records the system's interpretation, not necessarily a deliberate human act, malicious purpose or final outcome. Obtain technical explanation where generation is unclear.
The point to remember
Interpret an event from the system condition that generated it, not from its friendly label alone.