A security alert prompt should receive typed records with a source sensor, source event ID, event time, ingestion time, asset ID, rule ID, and parsing status. Event time and ingestion time are different: a delayed sensor may deliver a genuine earlier event after a later one. Normalize timestamps to a common comparison zone while retaining the raw timestamp and its offset. The model may summarize the records, but an application should reject missing keys and impossible time order before the analysis. Keep the original event pointer so an investigator can open the raw evidence instead of relying on a paraphrase.
Security alert prompts: preserve event provenance and time
Operational case
Orion Fleet receives 47 alert records from identity, endpoint, and network sensors. Identity event I-47 occurred at 09:14 but arrived at 09:23 after a network event from 09:19. Sorting by arrival would invert the sequence. The intake converts both to a common time basis and retains each sensor's raw value. One endpoint record lacks a host identifier; it goes to an unresolved bucket and is not attached to the nearest named host simply because the timestamps are close.
I-47 | identity | event 09:14 | ingested 09:23 | host H-47
N-51 | network | event 09:19 | ingested 09:20 | host H-47
E-09 | endpoint | host missing -> unresolved
Order by event time; retain source IDs and raw timesPerformance and review cost
Parsing and validating N alerts is O(N); sorting their event times is O(N log N). Carrying source pointers adds little space beside the records and saves investigation time when summaries disagree. A sensor clock may be wrong, so the normalized order is a working hypothesis until clock health is checked. The prompt should expose that uncertainty instead of presenting millisecond precision as certainty.
Common Mistakes
- Do not order events by ingestion time alone.
- Do not attach an alert to a host without a supported identity key.
- Do not discard raw sensor IDs after normalization.
Connected lessons
- Prompt engineering applications
- Prompt Engineering
- Research prompts: bind claims to a date and evidence record
- Dataset intake prompts: define a column before analyzing it
- Security alert prompts: group repeated signals without erasing events
- Security alert prompts: test benign explanations before escalation
- Security alert prompts: apply scoped severity and escalation rules
- Security alert prompts: quarantine instructions embedded in logs
- Security alert prompts: gate containment and verify receipts
- Project: triage Orion authentication alerts
- Security-alert triage decisions
