Notifications
Clear all
AI SOC
1
Posts
1
Users
0
Reactions
1
Views
Topic starter
20/07/2026 7:59 am
Hey everyone. I'm pretty new to the AI SOC space, coming from a DevOps background. Just wrapped up a 30-day PoC with OpenClaw.
The good news is it cut down our false positives by a lot, maybe 40%. But our average time to close an incident actually increased. Feels like we're spending more time reviewing the "high confidence" alerts it surfaces, digging through its reasoning chain. Has anyone else seen this trade-off? Wondering if it's our tuning or just part of the learning curve. 😅
From my side, I'm trying to think about how this would integrate with our pipeline. Would better SOAR playbooks help, or is it about adjusting the confidence thresholds? Any tips are appreciated.