> ## Documentation Index
> Fetch the complete documentation index at: https://docs.levelblue.com/llms.txt
> Use this file to discover all available pages before exploring further.

# System Events Management

An <Tooltip tip="Any traffic or data exchange detected by LevelBlue products through a sensor or external devices such as a firewall.">event</Tooltip> is a record of activity that contains information and resides in a log file. USM Anywhere collects, normalizes, and enriches logs with additional <Tooltip tip="Information about other associated data, used to help organize information, provide identification, support archiving of data, and other functions.">metadata</Tooltip>, which are called events.

USM Anywhere enables you to display system events. These events are any events generated within your environment. They are not <Tooltip tip="In USM Anywhere you can execute an action from alarms, events, and vulnerabilities to run a scan, get forensic information, or execute a response for a configured BlueApp.">actions</Tooltip> associated with any of the <Tooltip tip="Asset from which logs and other system status and event information is collected and processed.">monitored assets</Tooltip> or networks collected by your environment. For instance, the system generates a system event when an <Tooltip tip="An IP-addressable host, including but not limited to network devices, virtual servers, and physical servers.">asset</Tooltip>, a user, or a node is created, updated, or deleted or when you modify your multifactor authentication (<Tooltip tip="A method of access control in which a user is granted access only after successfully presenting several separate pieces of evidence to an authentication mechanism – typically at least two of the following categories: knowledge, possession, and inherence.">MFA</Tooltip>) subscription.

This topic discusses these subtopics:

* [USM Central System Events List View](/usm-central/system-events/system-events-list-view)
* [Searching System Events](/usm-central/system-events/searching-system-events)
* [Viewing System Event Details](/usm-central/system-events/viewing-system-events-details)
