// Operations

Metrics

Derived from stored timestamps rather than reported by a service. Where a measure cannot be computed honestly from what is recorded, it says so.

8alerts raised2incidents2containment actions
14.2h
Mean time to acknowledge
Alert raised until it left the new state
1.2d
Mean time to resolve
Across 1 closed incident
33%
False positive rate
Share of closed alerts dismissed as benign
63%
Escalation rate
Alerts that became incidents

Noisiest rules

Alert volume per rule. A rule at the top of this list is either finding a real campaign or needs tuning.

  • Bulk data egress2
  • Cloud access key created outside change hours1
  • Impossible travel1
  • Encoded PowerShell execution1
  • Office application spawning a script interpreter1
  • Mass file access1
  • Password spray against directory services1

Alert severity mix

  • Critical1
  • High3
  • Medium3
  • Low1
  • Info0

Analyst load

Open incidents by owner

  • Analyst1

Engine throughput

Every detection sweep is recorded, so this is measured rather than estimated.

No sweeps recorded

Run the detection engine from the alerts page to populate throughput.

Suppression effectiveness

How much noise each tuning rule has actually removed.

SuppressionFieldValueFindings removed
Backup agent file readsusernamesvc_backup0
Vulnerability scanner sweepssourceIp10.20.0.150