// Operations
Metrics
Derived from stored timestamps rather than reported by a service. Where a measure cannot be computed honestly from what is recorded, it says so.
8alerts raised2incidents2containment actions
14.2h
Mean time to acknowledge
Alert raised until it left the new state
1.2d
Mean time to resolve
Across 1 closed incident
33%
False positive rate
Share of closed alerts dismissed as benign
63%
Escalation rate
Alerts that became incidents
Noisiest rules
Alert volume per rule. A rule at the top of this list is either finding a real campaign or needs tuning.
- Bulk data egress2
- Cloud access key created outside change hours1
- Impossible travel1
- Encoded PowerShell execution1
- Office application spawning a script interpreter1
- Mass file access1
- Password spray against directory services1
Alert severity mix
- Critical1
- High3
- Medium3
- Low1
- Info0
Analyst load
Open incidents by owner
- Analyst1
Engine throughput
Every detection sweep is recorded, so this is measured rather than estimated.
No sweeps recorded
Run the detection engine from the alerts page to populate throughput.
Suppression effectiveness
How much noise each tuning rule has actually removed.
| Suppression | Field | Value | Findings removed |
|---|---|---|---|
| Backup agent file reads | username | svc_backup | 0 |
| Vulnerability scanner sweeps | sourceIp | 10.20.0.15 | 0 |