13
I finally stopped trusting our SIEM alerts after the 3AM false alarm
We spent two weeks chasing a critical alert that turned out to be a dev box sending test packets, and the on-call guy almost drove to the office in his pajamas. I learned to cross-check every alert against the actual source IP before waking anyone up, and now I want to know how many of you have tuned your SIEM to the point where you miss real threats instead?
0 comments
Log in to join the discussion
Log In0 Comments
No comments yet
Be the first to share your thoughts on this discussion.