Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is a user-generated event?

A user-generated event is produced in response to interaction through an account, session or interface. It is closer to human input than a routine background event, but it does not by itself identify the person behind that input.

The initiating action and its effects are different

Submitting a form, changing a setting or issuing a command may create one direct event and many automatic consequences. An application might then call APIs, write files, update a database and send notifications without further input.

The same apparent action may also be available through a script, administrator console or third-party integration. Product documentation and field definitions should establish what interaction the event actually represents.

Prove control separately from event type

Preserve account, session, device, source address and request identifiers, then relate them to authentication and endpoint evidence. Where the action required confirmation, reauthentication or multi-factor approval, establish whether those stages have their own records and whether they completed.

A sound conclusion may be that an action occurred within a particular session. Attributing it to the account holder additionally requires evidence about who controlled the device, credentials and session at that time.

The point to remember

“User-generated” describes the event's relationship to interaction, not conclusive attribution to the named account holder.

Reference: LOG-074Logs, Records & Provider Evidence