Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is a system log?

A system log is created by an operating system or core service about activity it observes while running a device or server. It is selective, not a complete neutral history.

Operating systems record defined categories

Events may cover startup, service failure, installation, device connection, accounts, configuration, errors and security. Entries can identify process, account, endpoint, event code, status and local time. Activity may come from a user, administrator, application, scheduled task, remote session or service.

Interpret source and sequence

Record operating-system version, log name, event code, configuration, field definitions and clock basis. Preserve nearby entries because meaning often depends on sequence and determine whether logging was enabled, rotated or altered in export.

Use the log to show what the system observed and add other evidence for person and purpose.

The point to remember

A system log describes selected operating-system observations whose meaning depends on configuration, time and surrounding events.

Reference: LOG-014Logs, Records & Provider Evidence