Viewing security rule alerts (lower part of the security rule page), they have wildly different fields (columns) that are useful to display. Customising them for one rule makes the view useless for another rule.
How could persistent fields (columns) be set per rule?
Was reading Customize SIEM Detection columns based on alert - #2 by Mike_Paquette about timelines and timeline templates. Created a timeline template with one desired column, set it as the default for the rule - but that did not make the column show up in the alert view or the timeline view (when opening it from a single alert). Timeline view filters for that single alert, thus customising the columns in the alert view seems like potentially a much more useful thing.