Alert, Event, Incident, and Offense: The Differences Every Analyst Needs to Know

An Event is a recorded activity or observation; an Alert is a notification generated when a detection mechanism finds a match or anomaly; an Incident is a collection of findings determined to require investigation and response; an Offense is IBM QRadar's investigation object, created from correlating Events and Flows based on Rules. The terms are not identical across products, so an analyst needs to understand both the general meaning and the data model of the tool they are working with.
A new analyst encounters similar words on every screen: Event, Alert, Incident, Case, Finding, and Offense. It’s easy to assume each describes a “cyber event,” but in practice, they represent different layers of data and decisions. This confusion impacts searching, documentation, metrics, and escalation.
NIST defines a Cybersecurity Incident as a cyber event determined to have an impact on the organization, thus requiring response and recovery. Microsoft describes an Incident as a collection of related Alerts that tell the story of an attack. IBM QRadar uses the term Offense for an actionable object created when Events and Flows meet Rule conditions. Therefore, it's impossible to automatically translate every term without understanding the context.
This guide builds the chain from raw log to investigation Case and explains where human decision-making comes in.




