Has anyone created a format for documenting their configured alerts/log rules in a nice way to read the flow (log rule -> alert or query -> alert or polling -> alert), easily see how it is configured and potentially filter based on conditions (i.e vendor, alert/rule names etc)?
Something we have always found difficult is to keep these documented in a manner that is easy to use and update.