🐿️
13

I finally stopped trusting our SIEM alerts after the 3AM false alarm

We spent two weeks chasing a critical alert that turned out to be a dev box sending test packets, and the on-call guy almost drove to the office in his pajamas. I learned to cross-check every alert against the actual source IP before waking anyone up, and now I want to know how many of you have tuned your SIEM to the point where you miss real threats instead?
0 comments

Log in to join the discussion

Log In
0 Comments

No comments yet

Be the first to share your thoughts on this discussion.