What should be preserved from firewall or security alerts?¶
Preserve the alert as a detection record: its full details, the rule that generated it, the surrounding events and the state of the interface before anyone acknowledges or changes it. A screenshot alone rarely captures enough context to interpret the alert later.
An alert records a system judgement¶
Firewalls and security platforms compare activity with rules, signatures, thresholds or behavioural models. The resulting severity and category describe what the product detected, not a proven account of what happened. False positives, incomplete visibility and product-specific naming all affect interpretation.
Capture the appliance or service, account, date, time zone and active filters. Preserve the alert ID, rule or signature, confidence, status and action, together with source and destination addresses, ports, protocol, direction, interface and session identifiers. Note whether traffic was allowed, blocked, challenged or quarantined.
Keep the alert connected to its evidence¶
Record the full list or dashboard before opening details, changing filters or marking the item as resolved. Acknowledgement and remediation can create audit entries or remove the original view. Where available, preserve linked raw events, connection logs or packet references through an approved process.
Correlate the alert with host, identity and network records using their clocks and retention periods. Geography, device labels and user names may be inferred or stale, so they should not be treated as attribution without corroboration.
Key takeaway
Preserve the alert, generating rule, identifiers, action and surrounding records before changing its state; it is evidence of a detection, not by itself proof of an attack or its author.