Hi there,
Yes, your theory seems right. There are five types of events that can be logged. All of these have well-defined common data and can optionally include event-specific data. The Event Viewer displays information about applications, security-related, systems, and set-up events.
Event Types https://learn.microsoft.com/en-us/windows/win32/eventlog/event-types
If you need to know the true process you can use other tools. Process Monitor is an advanced monitoring tool for Windows that shows real-time file system, Registry, and process/thread activity. You can get the tool from here https://learn.microsoft.com/en-us/sysinternals/downloads/procmon
------------------------------------------------------------------------------------------------------------------------------------------------------------
--If the reply is helpful, please Upvote and Accept it as an answer–