What is an alert?¶
An alert is a notification that data met a rule, threshold, signature, behavioural model or analyst condition. It is a lead and workflow event, not automatic proof of malicious activity.
Detection depends on data and rule design¶
Alerts may combine endpoint, firewall, identity, cloud or fraud records. Missing or delayed data and parsing errors can distort results, while legitimate activity can meet suspicious criteria. Severity may describe potential impact; detection time may follow event time; closure can record a workflow decision rather than an evidential finding.
Preserve rule and source context¶
Retain the alert, its updates, rule and version, thresholds, fields, source events, enrichments and analyst notes. Check whether several alerts arise from the same activity.
Use the alert to direct preservation and corroboration. Significant decisions should rely on understood underlying evidence and, where necessary, specialist explanation.
The point to remember
An alert proves that detection conditions were met; source records and rule logic establish what the activity means.