Skip to content
Skip to main content
Logs, Records & Provider Evidence Operational Explainer

Why should the rule version be preserved?

The version identifies the exact detection logic behind an alert and makes later interpretation repeatable. A rule name alone cannot show which fields, thresholds and exclusions applied.

Stable names can conceal material changes

Rules may retain a title while adding sources, changing a time window, altering severity or excluding known benign activity. Vendor-managed rules can update without an obvious local edit. Re-running today's rule may therefore produce a different result from the same events.

Version evidence is especially important where an alert informed containment, attribution or an enforcement decision and its technical basis may later be examined.

Preserve enough to reconstruct the match

Record rule ID, version, owner, source platform, effective date, logic and expected data sources. Keep linked deployment and change history. If the platform has no formal version, export the rule text and settings with a reliable timestamp; screenshots are secondary where a structured export is available.

Historical definitions may not be retained indefinitely. Capturing them while the investigation is live protects both the alert's meaning and a reviewer’s ability to test it.

The point to remember

Rule-version evidence preserves the precise logic needed to understand and reproduce an alert.

Reference: LOG-113Logs, Records & Provider Evidence