One of the main risks associated with deploying a SIEM is the number of alerts.

A misconfigured SIEM can generate:

  • hundreds of alerts;
  • thousands of alerts;
  • or even more depending on the size of the environment.

A security team that receives too many alerts eventually encounters a problem with:

fatigue alert.

The real objective is therefore not:

“Generate as many alerts as possible.”

It is rather:

“Generate the most relevant and actionable alerts.”

A good SIEM architecture must therefore include:

  • prioritization;
  • the criticality of the assets;
  • the criticality of users;
  • the context;
  • the thresholds;
  • the exceptions;
  • noise suppression;
  • the correlation;
  • enrichment.

Categories: