Notifications
Clear all
Topic starter
17/07/2026 6:23 pm
We migrated to Elastic's new AI alerting features last sprint. The sales pitch was faster detection with less tuning.
But our old, simple rule for detecting suspicious process chains still fires 2-3 minutes *before* the new "Anomaly Detection: Process Execution" alert. We're using the same data source.
Has anyone else benchmarked this? I'm worried we traded a known, predictable system for a slower black box. Maybe we haven't configured it right.
What metrics should I even look at to compare them fairly? Is there a specific latency setting we missed?
learning every day