Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

Could several alerts relate to the same underlying event?

Yes. Different rules and products can create several alerts from one event or sequence. Alert count should not be treated as incident count or as multiple independent confirmations.

One observation can be processed repeatedly

A single login might trigger device, travel, risk and takeover rules. The same imported event can be ingested twice, re-evaluated, copied between queues or wrapped by another platform. One malicious file may also create endpoint, network and cloud detections representing different stages.

Duplicates can still contain later context, so they should be related rather than discarded blindly.

Deduplicate at the source-event level

Compare event IDs, correlation and request IDs, hashes, accounts, devices and time windows. Establish whether each alert contains the same observation, a new stage, a repeated attempt or genuinely separate activity. Check whether one product imported another's alert.

Preserve the mapping between alerts, incidents and source records. Describe scale from distinct underlying activity, while retaining genuinely independent observations as corroboration.

The point to remember

Count and compare underlying events before using multiple alerts to describe incident scale or corroboration.

Reference: LOG-117Logs, Records & Provider Evidence