Skip to content
Crestline
Process

What is event log?

An event log is the raw material of process mining: a table where every row says which case moved, which step happened, and when.

Event log in plain words

Three columns are enough. The case is the thing travelling — an RA bill, a purchase order, a vendor invoice. The activity is the step that happened to it. The timestamp is when. Everything else is optional colour: amount, owner, vendor, project.

How is event log calculated?

case id + activity + timestamp

Anything that can export those three columns can be mined — SAP, Oracle, Tally, a ticketing system, or a spreadsheet.

Event log: a worked example

Four rows from a real-shaped event log for one purchase order.

PO-4417 · Requisition raised
02 Apr 2026 09:14
PO-4417 · PO issued
09 Apr 2026 16:02
PO-4417 · Goods received
21 Apr 2026 11:30
PO-4417 · Invoice paid
27 May 2026 14:07
What the log gives you
A 55-day journey with a 36-day gap between receipt and payment

Three columns — case, activity, timestamp — and the journey falls out. Nothing else in those rows is required.

Why does event log matter?

Your systems have been writing this log for years whether or not anyone reads it. It is the only record of what actually happened that nobody edited afterwards.

Where does event log mislead?

A log is only as honest as the moment the stamp is written. If an approval is entered in bulk on Friday for work done all week, the log shows one Friday spike and the real waiting time is invisible. Backdated entries are the single most common reason a mined duration is wrong.

What do people get wrong about event log?

Backdated and batched entries
Approvals keyed in weekly, GRNs entered at month end, POs raised after the invoice arrives. Each one moves a timestamp away from the event, and the delay in between simply stops existing in the data.
Dropping the rows that look wrong
Cases that skipped a step or ran out of order are usually the finding, not the dirty data. Filtering them out produces a clean map of a process nobody actually follows.
Assuming one system holds it all
Work that happens over email, on site or in a spreadsheet leaves no stamp. It shows up as one long unexplained wait — which is itself worth knowing, as long as it is read that way.

How does Crestline measure event log?

Crestline builds the event log from your ERP's own tables rather than asking you to produce one. The mapping from your field names to case, activity and timestamp is agreed once, then the log rebuilds itself on every sync.

30-minute discovery call

See your own event log, measured from your ERP.

Thirty minutes, read-only. Bring one question about your project cash and we will answer it from your own data — or tell you we cannot.

Book a 30-min callEmail us