Skip to content
Notifications
Clear all

Help: Our threat prevention logs are full of noise. How to filter meaningfully?

1 Posts
1 Users
0 Reactions
1 Views
(@cost_cutter_99)
Estimable Member
Joined: 4 months ago
Posts: 124
Topic starter   [#11070]

Our team recently switched to Prisma Access for our main remote user and branch security, and we're hitting a classic problem with a new tool: alert fatigue. The Threat Prevention logs are… a lot.

We're seeing thousands of "informational" entries daily—mostly for benign web tracking scripts, known-but-low-risk adware domains, and heuristic "suspicious" flags on public CDN resources. It's drowning out the actual medium/high severity items. Our SOC is complaining about the noise-to-signal ratio.

I've started digging into the policy rules and log forwarding settings, but the filtering feels blunt. Has anyone built a more surgical approach here?

* What's your practical method for categorizing and suppressing these noisy, low-fidelity alerts? Are you using custom Threat IDs, URL categories, or something else?
* Is there a way to structure the log forwarding to Splunk (our SIEM) to pre-filter this noise, or is it all done on the Prisma side?
* Any rule-of-thumb on what you *shouldn't* filter out? I'm wary of being too aggressive.

I'm planning to map the most frequent false positives against our actual incident history and build an exclusion list, but I'd love to hear how others have tuned this. Cost angle: the logging volume is also impacting our Splunk ingest, which has a direct cost per GB. Cleaning this up has a FinOps benefit too.



   
Quote