Usually logs are the records of all the actions that are performed on the system. Where in based on that logs we write rules/ correlation to build alerts. Alerts would be false positive or true incident, but not the logs as far as my knowledge is concern.

