Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is an alert?

An alert is a notification that data met a rule, threshold, signature, behavioural model or analyst condition. It is a lead and workflow event, not automatic proof of malicious activity.

Detection depends on data and rule design

Alerts may combine endpoint, firewall, identity, cloud or fraud records. Missing or delayed data and parsing errors can distort results, while legitimate activity can meet suspicious criteria. Severity may describe potential impact; detection time may follow event time; closure can record a workflow decision rather than an evidential finding.

Preserve rule and source context

Retain the alert, its updates, rule and version, thresholds, fields, source events, enrichments and analyst notes. Check whether several alerts arise from the same activity.

Use the alert to direct preservation and corroboration. Significant decisions should rely on understood underlying evidence and, where necessary, specialist explanation.

The point to remember

An alert proves that detection conditions were met; source records and rule logic establish what the activity means.

Reference: LOG-004Logs, Records & Provider Evidence