Skip to content
LOG-113 Logs, Records & Provider Evidence

Why should the rule version be preserved?

The rule version should be preserved because it identifies the exact detection logic that produced the alert.

Without it, later review may rely on a different rule with the same name.

Avoid the dangerous assumption

The dangerous assumption is that a rule name alone is enough to explain why the alert fired.

It is not.

Rules can change thresholds, fields, exclusions, severity and required event sequences while retaining the same title. A managed vendor rule may also update automatically without obvious local action.

The version helps another investigator, analyst or specialist reproduce the reasoning. It can show what data sources were expected, what conditions were required and how the result was classified.

Preserving the version is particularly important where the alert supports a significant decision, attribution or enforcement action. The exact logic may later be challenged.

Investigators should record the rule ID, version, effective date, owner and source platform. Obtain the rule logic or plain-language description that applied at the time.

Preserve any linked change history, deployment record and administrator audit event. If the rule was modified locally, record who changed it and why.

Where no formal version number exists, preserve the rule text, settings and screenshots as they appeared. A dated export or configuration record may provide the necessary reference.

Do not assume that the platform will retain historical rule definitions indefinitely. Collection should be considered while the investigation is live.

Operational takeaway

Preserving the rule version protects repeatability and accurate interpretation by showing the exact detection logic, thresholds and exclusions that produced the alert at the relevant time.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.