13
SIEM alert fatigue nearly cost us a real breach in Denver
Last quarter we had our SIEM screaming nonstop with false positives, like 400+ alerts a day. I got so used to tuning them out that I almost ignored a real credential dumping alert at 2 AM. It turned out to be an actual incident, and we only caught it cause a new guy asked what the noise was about. We cut our alert volume by 70% with better correlation rules, but has anyone else nearly missed something real because of alert fatigue? What's your threshold for when to silence a rule?
0 comments
Log in to join the discussion
Log In0 Comments
No comments yet
Be the first to share your thoughts on this discussion.