SIEM/Overview
Events 24h6%
2.4M
320 sample stream
Open alerts8
119
of 320
Critical open2
24
28 unowned open
MTT-triage4m
18m
7d median
True-positive3pp
41%
closed alerts
Fatigue p955
52
alerts fatigue ≥60

Security signal volume

Northline · weekly

Events ×kAlerts
0125251376501MonTueWedThuFriSatSun
Mon Okta connector deployWed EDR policy tightenThu VPN geo block updateSat SEV-1 identity-auth

Alert severity mix

open + recent

8
Critical
22
High
41
Medium
29
Low

Highest risk open

alerts ↑

AlertRiskSev
mail bec signal 7. samir.patel99Low
auth deny burst 4. host-wks-44298Medium
Auth deny burst. svc-auth98Medium
auth deny burst 28. contractor-jlee98Low
process lolbin 13. samir.patel96Low
auth token theft 19. host-edge-0796Low
Encoded PowerShell. marcus.chen95High

Entities needing attention

8 risk ≥ 60

Open Entities
EntityTypeRiskAlerts7d
host-edge-376Host927
svc-billingService9112
host-wks-119Host884
svc-worker-26Service866
host-edge-346Host868
amara.okaforUser845
svc-gw-39Service844
host-edge-07Host826

SOC posture

open work + fatigue

78
posture
4vs. prior week
Open alerts119
Critical open24
Unowned open28
Open incidents17
High fatigue52

Root-caused alerts

symptom → cause → fix

Do this next

scored from open risk · fatigue ROI · blast residual

Respond
#196
Contain SEV-1 credential storm
Stop lateral to finance
Hours
#294
Suppress brute-force flap cluster
−38 analyst hours/week
Minutes
#390
Rotate svc-billing keys
Close SEV-2 exfil path
Hours
#486
Own 6 unowned critical alerts
Triage SLA recovery
Hours
Operator console