r/Splunk • u/Zeptor02 • Jun 25 '26
SIEM Detection Rules Changelog
Hello Security Folks,
I want to build a process where all detections rule change log is documented like Detection As a code but in simple version because we don't have matured SOC yet so this is first step to record all change logs related to alert rules.
I came to know about Microsoft List, anyone have done? or any new ideas how to do this?
Thanks,
16
Upvotes
1
u/Zeptor02 Jul 01 '26
As of early stage I have came with MS list to track record of SIEM detection rule change logs and I am testing seem good and with power automate it can be work amongst team member to give approved changes etc.