Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is the difference between an alert and the underlying evidence?

The alert is a system's conclusion or notification; the underlying evidence is the source data and configuration from which that conclusion was produced.

Summaries omit alternatives and detail

An “impossible travel” alert may reduce two authentication events, timestamps, addresses, endpoint fields and estimated locations to one label. VPN, mobile routing, stale sessions, ingestion time or enrichment error may change the interpretation. A screenshot rarely exposes the rule or all contributing records.

Reconstruct the detection

Preserve the alert because it can show organisational awareness and response. Obtain original events, relevant time window, raw fields, definitions, rule and version, enrichment sources and analyst notes.

Test parsing, grouping and alternative explanations before repeating the label as fact. Where source material is unavailable, state that the alert summary cannot independently establish the underlying conduct.

The point to remember

Keep the alert as evidence of detection, but base conclusions on the records and logic that generated it.

Reference: LOG-005Logs, Records & Provider Evidence