Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is a system-generated event?

A system-generated event is written automatically by a device, operating system, service or application as part of its operation. No person needs to perform a new action when the entry is created.

Automatic does not mean unimportant

Service starts, health checks, updates, token renewals, indexing, network reconnection and security scans can all create records. The event may explain why a process ran, a policy changed or later activity became possible.

Its account field can be easy to misread. Software may run as a system or service identity, or within the security context of whoever is logged in. The named account therefore describes execution context unless the event definition says more.

Normal triggers help explain the record

Establish the event source, generating process or service, configured trigger and relationship to preceding entries. Task definitions, service configuration, process ancestry and repeated occurrences on comparable systems can show whether it is routine behaviour or an unusual invocation.

An automatic event may still be maliciously caused - for example, where an attacker alters a scheduled process. The record supports what the system did; evidence about configuration changes and access is needed to explain who set it in motion.

The point to remember

Interpret a system-generated event through its component and trigger, not as automatic proof of human action.

Reference: LOG-073Logs, Records & Provider Evidence