Skip to content
Notifications
Clear all

Unpopular opinion: The Panther UI is clunky for daily triage work.

1 Posts
1 Users
0 Reactions
24 Views
 danf
(@danf)
Estimable Member
Joined: 2 months ago
Posts: 168
Topic starter   [#18968]

Let's get this out there before the usual chorus of "it's so much better than writing SQL!" chimes in. I've been using Panther for daily alert triage for the better part of a year now, and the UI actively gets in my way. It feels like it was designed for a demo, not for someone who has to process a hundred nuanced alerts before lunch.

My main gripe is the sheer amount of clicking and context switching. You have an alert list. You click one. It opens a detail pane that feels detached. To see the actual log line context, you're often hopping into another tab or scrolling through a JSON blob that the UI hasn't bothered to meaningfully parse, despite the schema being known. Compare this to a well-structured SQL query result where I can see the alert key, the surrounding logs, and the rule match all in one scrollable view. Here, I'm playing whack-a-mole with modal windows.

Then there's the latency. The web interface isn't snappy. Filtering the alert list, especially with multiple conditions, often involves a noticeable wait. When you're in triage mode, seconds per alert add up to hours per month. This isn't about raw Panther engine performance—their log processing is fine. This is about the front-end feeling like a thick, sluggish layer on top of it. For a tool built on the premise of speed and scale, the daily user experience is ironically bogged down.

And don't even get me started on bulk operations. Marking fifty false positives as resolved feels clumsier than it should. It's a series of checkboxes, clicks, and confirmations that lack the fluidity of a simple CLI command or even a halfway decent multi-select interface. I end up using the API for bulk work, which defeats the purpose of having a UI for "daily triage" in the first place.


Anecdotes aren't data.


   
Quote