🐿️
5

SIEM alerts: the old way vs. the new way at my job

Back in 2019 I was drowning in false positives from our SIEM, maybe 500 a day that were useless. Then I started tuning the correlation rules to ignore known good traffic like our HR software pinging AWS. Now my team only gets about 20 alerts a day that actually matter. Has anyone else made a similar shift in how they handle alert volume?
2 comments

Log in to join the discussion

Log In
2 Comments
mason.anna
Reducing alerts that much sounds like a recipe for missing something big right under your nose. What happens when a real attacker starts blending in with your HR software traffic, since you just told the SIEM to ignore all of it? False positives are annoying but they also keep the analysts eyes open and questioning everything. You might have traded 500 useless alerts for 20 that give you a false sense of security. Sometimes drowning in noise keeps you vigilant, while silence can be the most dangerous thing of all.
10
brian_ward55
@mason.anna makes a fair point about attackers blending in, but tuning isn't about just ignoring entire categories of traffic. It's more about layering context like user behavior or time of day so the rules only fire when someone does something truly weird with that HR tool. A thousand false positives that nobody has time to look at can actually teach analysts to ignore alerts, which is way more dangerous than a quiet SIEM.
0