Skip to content
Notifications
Clear all

Where to start tuning? We get 500+ items a day.

1 Posts
1 Users
0 Reactions
0 Views
(@danm)
Reputable Member
Joined: 3 weeks ago
Posts: 203
Topic starter   [#23824]

We've been using CrowdStrike Intel for a few months now, and the volume is just overwhelming. Our security team is getting buried. We're seeing over 500 items a day, and it's clear we need to tune the filters, but the sheer number of sources and rules is a bit paralyzing.

For those who've been through this, where's the most effective place to start? I'm thinking about adjusting the default alerting rules or maybe curating our intel sources first. Looking for practical first steps that actually reduced noise for your team.



   
Quote