The event log is the black box of a control system. It is the timestamped, chronological record of everything that happened - alarms, operator actions, mode changes, communications drops - and it is what investigators, auditors, and the next shift rely on to reconstruct what took place. This guide explains what an event log captures and why it matters.
Event Log in one line: An event log is a chronological, timestamped record of significant occurrences in a SCADA or control system: alarms activating and clearing, operators acknowledging alarms and issuing commands, setpoint and mode changes, logins, and system events such as communication failures. Unlike the alarm summary, which shows only what is active now, the event log is a permanent history used for shift review, incident investigation, and audit.
A comprehensive event log captures three broad categories. First, alarm events: every time an alarm goes active, is acknowledged, and returns to normal, each stamped with the exact time. Second, operator actions: setpoint changes, valve open/close commands, pump starts and stops, mode switches from auto to manual, and alarm shelving, each attributed to the user who performed it. Third, system events: controller communication losses, device faults, logins and logouts, and configuration changes.
Every entry carries a precise timestamp, and in systems with tight time synchronization these are accurate to the millisecond. That precision is what makes a specialized form of the event log - the sequence of events (SOE) record - so useful: when a trip cascades through interlocks in a fraction of a second, high-resolution timestamps reveal the exact order in which events occurred, which the human eye could never resolve.
When something goes wrong, the event log is the primary evidence. Investigators walk the log backward from the incident to find the initiating event and the sequence that followed, and to see what the operator did and when. A well-kept log turns a vague 'the compressor tripped last night' into a precise timeline: high vibration alarm at 02:14:07, operator acknowledged at 02:14:41, trip at 02:14:52.
The event log also serves shift handover and compliance. The oncoming operator reviews the log to understand what happened while they were away. Auditors use it as an audit trail to confirm who changed what and when, which matters for regulated operations. In oil and gas, event logs support incident and spill investigations, custody and operational disputes, and the routine business of understanding a facility's behavior over time. Because logs are legal and operational records, they are typically stored securely and retained for defined periods.
The alarm summary is a live view of currently active alarms - what needs attention now. The event log is a permanent chronological history of everything that happened, including alarms that have already cleared, operator actions, and system events. You act from the summary and investigate from the log.
An SOE is a high-resolution form of event log, with timestamps accurate to the millisecond, used to establish the exact order of rapid events during a trip or cascade. It relies on precise time synchronization so events across different devices can be correctly ordered.
Yes. Merobix records timestamped events - alarm transitions, operator acknowledgements and commands, and system events - creating a chronological log operators can review for shift handover, investigations, and audit.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.