One of the main risks associated with deploying a SIEM is the number of alerts.
A misconfigured SIEM can generate:
- hundreds of alerts;
- thousands of alerts;
- or even more depending on the size of the environment.
A security team that receives too many alerts eventually encounters a problem with:
fatigue alert.
The real objective is therefore not:
“Generate as many alerts as possible.”
It is rather:
“Generate the most relevant and actionable alerts.”
A good SIEM architecture must therefore include:
- prioritization;
- the criticality of the assets;
- the criticality of users;
- the context;
- the thresholds;
- the exceptions;
- noise suppression;
- the correlation;
- enrichment.