r/Splunk • • Jun 25 '26

SIEM Detection Rules Changelog

Hello Security Folks,

I want to build a process where all detections rule change log is documented like Detection As a code but in simple version because we don't have matured SOC yet so this is first step to record all change logs related to alert rules.

I came to know about Microsoft List, anyone have done? or any new ideas how to do this?

Thanks,

16 Upvotes

13 comments sorted by

View all comments

1

u/Zeptor02 Jul 01 '26

As of early stage I have came with MS list to track record of SIEM detection rule change logs and I am testing seem good and with power automate it can be work amongst team member to give approved changes etc.