Skip to content
Notifications
Clear all

Hot take: Their new 'AI-powered' alerting isn't faster than our old rule set, prove me wrong.

1 Posts
1 Users
0 Reactions
24 Views
(@benjic)
Estimable Member
Joined: 3 months ago
Posts: 116
Topic starter   [#9405]

We migrated to Elastic's new AI alerting features last sprint. The sales pitch was faster detection with less tuning.

But our old, simple rule for detecting suspicious process chains still fires 2-3 minutes *before* the new "Anomaly Detection: Process Execution" alert. We're using the same data source.

Has anyone else benchmarked this? I'm worried we traded a known, predictable system for a slower black box. Maybe we haven't configured it right.

What metrics should I even look at to compare them fairly? Is there a specific latency setting we missed?


learning every day


   
Quote