Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

Could a rule change after the event?

Yes. Detection rules are revised to change logic, sources, thresholds, exclusions and severity. A current rule - even with the same name - may not explain an older alert.

Rule behaviour is time-dependent

Security teams tune rules to reduce false alerts or cover new techniques, and vendors may update managed content automatically. A later version can use a different time window or require a different event sequence, so it may not reproduce the original result.

The alert remains evidence of what the platform generated then. It should be interpreted against the logic and data effective at that point, rather than validated or rejected using a later improvement.

Recover the historical configuration

Preserve the alert's rule ID, name, version and logic summary with its linked events. Change audits, deployment records and vendor release notes may establish effective dates where old definitions are not retained.

Record any uncertainty if the historical logic cannot be recovered. The present configuration can provide context, but should not be presented as the rule that fired without evidence of continuity.

The point to remember

Explain an alert using the rule version active when it was generated, not today's rule or title alone.

Reference: LOG-112Logs, Records & Provider Evidence