> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wirespeed.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Introduction to Events

> Ingest events, logs, and more from your source system into Wirespeed's SIEM

Wirespeed stores events from your integrations in its SIEM and normalizes key activity for cross-source investigation.

## Event views

* **Explore** searches SIEM 2.0 vendor and normalized tables with Wirespeed Expression Language (WEL).
* **Advanced** runs SQL for manual analysis and exports.
* **Legacy** remains available for teams with retained OCSF events.

Create [custom detections](/events/custom-detections) with **Ask Wirespeed**, not from Advanced. The assistant inspects your connected schema, builds a source-aware WHERE predicate, executes it under the production limits, and shows the match count before you confirm.

Some ingested events are tagged as productivity activity (mailbox and related collaboration actions). That data powers features such as the **Identity Login** case monitor. If you see a timeline note that productivity logs are not available, the monitor needs more of that event volume in Wirespeed—see [Case monitors and productivity logs](/verdicts/introduction#case-monitors-and-productivity-logs).
