# SOC practitioner verbatim excerpts

**Prepared for Susie Fan.** This download contains one short, unchanged excerpt from each of the 226 selected core source records, followed by separate product-feedback, concept-validation, and named-source excerpts. It is an excerpt collection, not full post transcripts or a representative survey. Public handles and roles are as recorded in the research ledger; identities were not independently verified. Ellipses in the original collection mark truncation. The source links lead to the original posts or articles.

## Core collection: 226 selected source records

### E01 — Shift handovers lose current context

**Original source:** [Shift handovers lose current context](https://www.reddit.com/r/cybersecurity/comments/1q4yg9i/how_to_deal_with_shift_changes/)
**Voice:** Possible-Error-317
**Date as recorded:** 2026-01-05; date surfaced by original page/search

> I've tried a shared OneNote with several tabs for different clients

### E02 — Outsourced investigations cannot be reconstructed

**Original source:** [Outsourced investigations cannot be reconstructed](https://www.reddit.com/r/cybersecurity/comments/1rdu73c/expected_soc_documentation_quality_per_incident/)
**Voice:** PerformerWrong8564
**Date as recorded:** Page displayed 7mo ago; exact publication date not captured

> Often, key triage decisions, analysis steps, and investigation context are missing.

### E03 — Analysts rebuild missing detection knowledge

**Original source:** [Analysts rebuild missing detection knowledge](https://www.reddit.com/r/cybersecurity/comments/1pxj7i9/what_is_the_false_positive_rate_in_your_soc/)
**Voice:** Silver-Neckbeard
**Date as recorded:** 2025-12-28; exact date surfaced in expanded search

> As a result, I spend hours researching each new alert type and writing my own playbooks before triage.

### E04 — Junior analysts struggle with investigation completeness

**Original source:** [Junior analysts struggle with investigation completeness](https://www.reddit.com/r/cybersecurity/comments/1ldwx2y/handling_mistakes_as_level_1_soc_analyst/)
**Voice:** cautiously-excited
**Date as recorded:** Approximately June 2025; precise date not captured

> I should have looked at more than just the last week of logs

### E05 — Major incidents outgrow a shared understanding

**Original source:** [Major incidents outgrow a shared understanding](https://www.reddit.com/r/cybersecurity/comments/1wm1afy/cirtincident_response_people_how_do_you_handle_it/)
**Voice:** hoydpc31
**Date as recorded:** 2026-09-21 in search result; cached relative age varied

> The IOCs keeps expanding, the scope of investigation keeps multiplying

### E08 — Severity does not establish business importance

**Original source:** [Severity does not establish business importance](https://www.reddit.com/r/cybersecurity/comments/1rdwdse/soc_analysts_what_actually_slows_down_your_alert/)
**Voice:** lucas_parker2; corroborating reply T_Thriller_T
**Date as recorded:** February 2026 in search; page displayed 7mo ago

> Alerts that come in with zero business context attached are basically homework assignments with no answer key.

### E14 — Phishing response gets stuck after the verdict

**Original source:** [Phishing response gets stuck after the verdict](https://www.reddit.com/r/cybersecurity/comments/xma750/effectiveness_of_responding_to_reported_phishing/)
**Voice:** Copper_Mind
**Date as recorded:** 2022-09-23 in search result; historical example

> the hassle of going through change management really drags the process out.

### E15 — AI can help preparation while increasing review burden

**Original source:** [AI can help preparation while increasing review burden](https://www.reddit.com/r/cybersecurity/comments/1wny3gh/has_ai_actually_helped_anyone_here_with_alert/)
**Voice:** Sqooky; ZeMuffenMan; thekmanpwnudwn
**Date as recorded:** September 2026; recent thread, exact publication date not retained

> We've seen lack of evidence in AI be interpreted as no problem.

### E16 — Promising AI trials still need context and prolonged validation

**Original source:** [Promising AI trials still need context and prolonged validation](https://www.reddit.com/r/cybersecurity/comments/1p4quu9/comment/nqe0bj8/)
**Voice:** cornaholic
**Date as recorded:** 2025-11-23 in search result; cached relative age varied

> Our POC results were good enough to warrant a bigger investment and extended trialing.

### E17 — Phishing automation still routes ambiguous mail to people

**Original source:** [Phishing automation still routes ambiguous mail to people](https://www.reddit.com/r/cybersecurity/comments/1sywuwj/daily_soc_analyst_pain_points/)
**Voice:** omers
**Date as recorded:** 2026-04-29

> Our report phishing button still feeds into automation and AI with some custom rules tossed in.

### E19 — Closed tickets hide workload strain

**Original source:** [Closed tickets hide workload strain](https://www.reddit.com/r/cybersecurity/comments/1n0isd1/burnout_in_soc_cyber_teams_does_hr_ever_really/)
**Voice:** Unexpected_Wave
**Date as recorded:** 2025-08-26

> From the outside everything looks fine - tickets are closed, incidents resolved

### E20 — Repetitive alert work and thin procedures undermine retention

**Original source:** [Repetitive alert work and thin procedures undermine retention](https://www.reddit.com/r/cybersecurity/comments/1ocq23r/burnt_out_and_bored_at_msp/)
**Voice:** Critical-Current-263
**Date as recorded:** 2025-10-21

> we r drowning in alerts

### E21 — Restoring service can erase context another responder wanted

**Original source:** [Restoring service can erase context another responder wanted](https://www.reddit.com/r/cybersecurity/comments/163rvuf/messed_up_on_my_first_real_incident_response_help/)
**Voice:** LuckyAd4953
**Date as recorded:** 2023-08-28

> Thinking this was just some weird quirk with her new computer, I cleared the rules

### E22 — Access to incident findings is contested

**Original source:** [Access to incident findings is contested](https://www.reddit.com/r/cybersecurity/comments/17l1x3v/incident_response_report/)
**Voice:** digitydog70
**Date as recorded:** 2023-11-01

> I had some conversations and one individual said, you don't need it.

### E23 — A near miss exposes detection blind spots

**Original source:** [A near miss exposes detection blind spots](https://www.reddit.com/r/cybersecurity/comments/1ksr067/after_every_incident_is_it_normal_to_realise_that/)
**Voice:** accountability_bot
**Date as recorded:** 2025-05-22

> if a redis instance didn’t trigger a warning for suddenly having more keys than normal

### E24 — Benign administrative activity is repeatedly investigated

**Original source:** [Benign administrative activity is repeatedly investigated](https://www.reddit.com/r/cybersecurity/comments/1och2bi/false_positives/)
**Voice:** Immediate_Brick_3999
**Date as recorded:** 2025-10-21

> I’m mistaking False Positives for Benign events.

### E25 — Repeat alerts persist when customers do not engage

**Original source:** [Repeat alerts persist when customers do not engage](https://www.reddit.com/r/cybersecurity/comments/1kdojiw/soc_life/)
**Voice:** Roushstage2
**Date as recorded:** 2025-05-03

> They never respond when we reach out to them regarding it.

### E26 — An outsourced SOC feels like an alert relay

**Original source:** [An outsourced SOC feels like an alert relay](https://www.reddit.com/r/cybersecurity/comments/1i83x05/is_our_soc_useless_how_to_improve_it/)
**Voice:** fcsar
**Date as recorded:** 2025-01-23

> we receive the same alerts as SOC tickets

### E27 — Junior analysts need help beyond generic playbooks

**Original source:** [Junior analysts need help beyond generic playbooks](https://www.reddit.com/r/cybersecurity/comments/1la36id/improving_soc_team_efficiency_seeking_best/)
**Voice:** Rahulisationn
**Date as recorded:** 2025-06-13

> the nature of the custom alerts makes playbooks insufficient.

### E28 — Multi-client operations vary with integration and visibility

**Original source:** [Multi-client operations vary with integration and visibility](https://www.reddit.com/r/cybersecurity/comments/1802jnp/managed_socmdretc_anyone_ever_work_in_one_how_is/)
**Voice:** Kryyses
**Date as recorded:** 2023-11-20

> The worst company had everything in separate tools and a spreadsheet to help you figure out who owned what assets.

### E29 — Escalations meet customer silence

**Original source:** [Escalations meet customer silence](https://www.reddit.com/r/cybersecurity/comments/1c5bi7j/soc_clients/)
**Voice:** Hot_Employer5169
**Date as recorded:** 2024-04-16

> not respond to emails and phone calls regarding security alerts?

### E30 — The senior analyst becomes the bottleneck for many jobs

**Original source:** [The senior analyst becomes the bottleneck for many jobs](https://www.reddit.com/r/cybersecurity/comments/1qgqdbq/leaving_the_mssp_space/)
**Voice:** PhilosopherPanda
**Date as recorded:** 2026-01-19

> I am the last escalation point for anything technical

### E34 — Throughput feedback does not teach investigation quality

**Original source:** [Throughput feedback does not teach investigation quality](https://www.reddit.com/r/cybersecurity/comments/1cprny5/if_youre_a_t1_soc_analyst_how_do_you_get_feedback/)
**Voice:** RandomgRandom; counterexample madmorb
**Date as recorded:** 2024-05-11

> Never really got any feedback on my actual ability to triage.

### E35 — Investigation depth conflicts with ticket targets

**Original source:** [Investigation depth conflicts with ticket targets](https://www.reddit.com/r/cybersecurity/comments/j0wj47/quantity_or_quality_for_soc_teams/)
**Voice:** vhlr
**Date as recorded:** 2020-09-27

> i have to “degrade” the quality of my work

### E36 — A quiet environment makes SOC value hard to demonstrate

**Original source:** [A quiet environment makes SOC value hard to demonstrate](https://www.reddit.com/r/cybersecurity/comments/1nl4c3w/advice_needed_leadership_wants_impactful_results/)
**Voice:** Kermody
**Date as recorded:** 2025-09-19

> Leadership asked me to come up with "visible, impactful results"

### E37 — Integrated intake helps, but reporting stays awkward

**Original source:** [Integrated intake helps, but reporting stays awkward](https://www.reddit.com/r/cybersecurity/comments/1jgifvx/moving_to_servicenow_any_tips_for_cyber_related/)
**Voice:** ronpatron23
**Date as recorded:** 2025-03-21

> create tickets for issues that people reach out to me via Slack with one click.

### E38 — Ambiguous ticket status creates duplicate handover work

**Original source:** [Ambiguous ticket status creates duplicate handover work](https://www.reddit.com/r/cybersecurity/comments/w69hz9/what_is_the_most_annoyingtime_consuming/)
**Voice:** Biggsdrasil
**Date as recorded:** 2022-07-23

> the offshore team apparently gets told to do things differently than us

### E43 — Automation accumulates maintenance debt

**Original source:** [Automation accumulates maintenance debt](https://www.reddit.com/r/cybersecurity/comments/1lt5v5g/soar_best_practices/)
**Voice:** einzwell
**Date as recorded:** 2025-07-06

> I'll most likely need to rebuild most of the automation we currently have

### E44 — A solo operator needs low upkeep and controlled data retention

**Original source:** [A solo operator needs low upkeep and controlled data retention](https://www.reddit.com/r/cybersecurity/comments/1urzvab/siem_solution_recommendations/)
**Voice:** Puzzleheaded_Art6665
**Date as recorded:** 2026-07-09

> I'll be the one deploying and running the SIEM myself

### E45 — Customer-specific automation may not scale

**Original source:** [Customer-specific automation may not scale](https://www.reddit.com/r/cybersecurity/comments/1wa8vj7/what_are_you_guys_doing_to_actually_scale/)
**Voice:** cluesthecat
**Date as recorded:** 2026-09-08

> every new customer, rule, data source, or workflow creates more manual work for the team.

### E47 — Hunts need bounded questions and deliverables

**Original source:** [Hunts need bounded questions and deliverables](https://www.reddit.com/r/cybersecurity/comments/1kfh2t2/how_do_you_approach_threat_hunting_in_practice/)
**Voice:** Polaris44
**Date as recorded:** 2025-05-05

> to prevent rabbit holes, I always have a clear start/end date

### E48 — Natural-language querying is not universally valuable

**Original source:** [Natural-language querying is not universally valuable](https://www.reddit.com/r/cybersecurity/comments/1huzdkd/what_does_threat_hunting_look_like_at_your/)
**Voice:** ZGFya2N5YmU
**Date as recorded:** 2025-01-06

> I’ve rarely felt the need or urge to use it.

### E49 — Advanced hunting requires repeatable analytical pipelines

**Original source:** [Advanced hunting requires repeatable analytical pipelines](https://www.reddit.com/r/cybersecurity/comments/1cv9l1f/does_anyone_perform_modelassisted_threat_hunting/)
**Voice:** WadeEffingWilson
**Date as recorded:** 2024-05-18

> Scaling is always an issue

### E50 — Incident reporting can be automated without generative AI

**Original source:** [Incident reporting can be automated without generative AI](https://www.reddit.com/r/cybersecurity/comments/1khi2ub/can_data_analysisscience_and_cybersecurity_be/)
**Voice:** Visible_Mess_9985
**Date as recorded:** 2025-05-08

> yesterday I made a notebook that uses pandas to automate the report generation process

### C001 — Need more further insight from more experienced SOC analyst

**Original source:** [Need more further insight from more experienced SOC analyst](https://www.reddit.com/r/cybersecurity/comments/1wmiiow/need_more_further_insight_from_more_experienced/)
**Voice:** Lorentz90
**Date as recorded:** September 21 2026 (search-index date)

> We have no tiers, so we do a case (alert) from start to finish

### C002 — SOC analysts — what’s your triage workflow like?

**Original source:** [SOC analysts — what’s your triage workflow like?](https://www.reddit.com/r/cybersecurity/comments/1okmjeh)
**Voice:** Mark_in_Portland
**Date as recorded:** October 31 2025 (search-index date)

> I sometimes want to pull my hair out if the only note is "not malicious" or "resolved"

### C005 — Using AI in SOC

**Original source:** [Using AI in SOC](https://www.reddit.com/r/cybersecurity/comments/1r5yiq5/using_ai_in_soc/)
**Voice:** OkReading3238
**Date as recorded:** February 16 2026 (search-index date)

> I’ve personally used it to analyze a large amount of somd sketchy logs, but hallucinations killed that dream lol.

### C007 — Help with SOC Alert Fatigue

**Original source:** [Help with SOC Alert Fatigue](https://www.reddit.com/r/cybersecurity/comments/1rcpv5v/help_with_soc_alert_fatigue/)
**Voice:** cautiously-excited
**Date as recorded:** February 23 2026 (search-index date)

> However, my team has been onboarding new clients without really tuning many alerts. As a result the number of alerts …

### C013 — how many alerts do you actually look at vs quietly ignore?

**Original source:** [how many alerts do you actually look at vs quietly ignore?](https://www.reddit.com/r/cybersecurity/comments/1qegs8t/how_many_alerts_do_you_actually_look_at_vs/)
**Voice:** Palmelicangel
**Date as recorded:** January 16 2026 (search-index date)

> We tune, suppress, reprioritise, tweak rules… and still finish the day knowing a big chunk never even got opened. And …

### C014 — SOC teams: how many alerts are you approximately handling every day?

**Original source:** [SOC teams: how many alerts are you approximately handling every day?](https://www.reddit.com/r/cybersecurity/comments/1fuasly/soc_teams_how_many_alerts_are_you_approximately/)
**Voice:** woaq1
**Date as recorded:** October 02 2024 (search-index date)

> Our detections in SIEM isn’t our only vertical for alerting

### C156 — How do you use your SIEM?

**Original source:** [How do you use your SIEM?](https://www.reddit.com/r/cybersecurity/comments/1jvmd67)
**Voice:** PriorFluid6123
**Date as recorded:** Page displayed 1y ago; exact date unverified

> I'm looking to optimize our SIEM setup and would love your input:

### C158 — SOAR Usecases

**Original source:** [SOAR Usecases](https://www.reddit.com/r/cybersecurity/comments/1fyeozl)
**Voice:** SecretSilence69
**Date as recorded:** October 07 2024 (search-index date)

> SOC Manager wants to implement SOAR. What security use cases do you have?

### C159 — What is the coolest SOAR automations you’ve seen?

**Original source:** [What is the coolest SOAR automations you’ve seen?](https://www.reddit.com/r/cybersecurity/comments/17cp9y0)
**Voice:** AverageAdmin
**Date as recorded:** October 20 2023 (search-index date)

> When I joined the team, they had a mailbox for the phishing submissions along with the SIEM alert that were …

### C160 — How much of your security ops have you automated — and what’s your biggest win?

**Original source:** [How much of your security ops have you automated — and what’s your biggest win?](https://www.reddit.com/r/cybersecurity/comments/1jihbfb)
**Voice:** CyberRabbit74
**Date as recorded:** March 24 2025 (search-index date)

> we have blocked IP addresses only to have to unblock them later when a member of the public complains

### C162 — How do you actually automate your security processes?

**Original source:** [How do you actually automate your security processes?](https://www.reddit.com/r/cybersecurity/comments/1gybk37/how_do_you_actually_automate_your_security/)
**Voice:** HappyDoodi
**Date as recorded:** November 24 2024 (search-index date)

> After several months of implementation, we've hit a reality check: ✓ What's working: Basic IR workflows (PagerDuty integrations, etc.)

### C165 — Hey cybersecurity peeps, what have you automated?

**Original source:** [Hey cybersecurity peeps, what have you automated?](https://www.reddit.com/r/cybersecurity/comments/1cmbasf/hey_cybersecurity_peeps_what_have_you_automated/)
**Voice:** ThePorko
**Date as recorded:** May 07 2024 (search-index date)

> I have always heard “automate everything” there are very few things I have been able to automate, with MS security …

### C175 — Soc analyst how do you guys do it?

**Original source:** [Soc analyst how do you guys do it?](https://www.reddit.com/r/cybersecurity/comments/16rdxge)
**Voice:** General-Example-3837
**Date as recorded:** September 25 2023 (search-index date)

> It’s not the work load but the hours I work that take a toll in my body. Recently got my …

### C181 — Seeking Automation Inspiration for SOC/Blue Teams

**Original source:** [Seeking Automation Inspiration for SOC/Blue Teams](https://www.reddit.com/r/cybersecurity/comments/13wwp64)
**Voice:** JordanSui
**Date as recorded:** May 31 2023 (search-index date)

> I'm a T2 cyber security analyst working on implementing new automations in our SOC. Tomorrow, I have a meeting with …

### C183 — Automation Playbooks - which ones would you not want to live without?

**Original source:** [Automation Playbooks - which ones would you not want to live without?](https://www.reddit.com/r/cybersecurity/comments/1u0jhgc/automation_playbooks_which_ones_would_you_not/)
**Voice:** Oompa_Loompa_SpecOps
**Date as recorded:** June 08 2026 (search-index date)

> We consume MDR services and use them to filter signal from noise, but drive response ourselves. I have run a …

### C236 — I'm a CISO who has built a successful security metrics and reporting program - Ask Me Anything about demonstrating security's value to the business.

**Original source:** [I'm a CISO who has built a successful security metrics and reporting program - Ask Me Anything about demonstrating security's value to the business.](https://www.reddit.com/r/cybersecurity/comments/1iah488/im_a_ciso_who_has_built_a_successful_security/)
**Voice:** Krekatos
**Date as recorded:** January 26 2025 (search-index date)

> we automated most metrics by capturing information from endpoints, tickets, threat landscape and much more

### C242 — Building a SOC , Advices based on experience needed.

**Original source:** [Building a SOC , Advices based on experience needed.](https://www.reddit.com/r/cybersecurity/comments/1gejxdj)
**Voice:** Justepic1
**Date as recorded:** October 29 2024 (search-index date)

> the number one thing you need to focus on is your stack and getting people trained in those systems.

### C243 — Is the situation at my SOC normal?

**Original source:** [Is the situation at my SOC normal?](https://www.reddit.com/r/cybersecurity/comments/17fdasv/is_the_situation_at_my_soc_normal/)
**Voice:** SorryPalpitation9680
**Date as recorded:** Page displayed 3y ago; exact date unverified

> There are a lot of complaints at my company from my co-workers and the general attitude we get from our …

### C244 — How to improve my incident response

**Original source:** [How to improve my incident response](https://www.reddit.com/r/cybersecurity/comments/1rl2vfe/how_to_improve_my_incident_response/)
**Voice:** Complex-Round-8128
**Date as recorded:** March 05 2026 (search-index date)

> I recently started a new position as an Incident Responder.

### C252 — How is it like working in Incident Response?

**Original source:** [How is it like working in Incident Response?](https://www.reddit.com/r/cybersecurity/comments/sp8a2c)
**Voice:** Beef_Studpile
**Date as recorded:** February 10 2022 (search-index date)

> Once I identify gaps, or engineer a new solution to prevent the incidents from happening again, I work with other teams

### C254 — Does someone has experience working as Incident Response role? Can you explain what do you do daily?

**Original source:** [Does someone has experience working as Incident Response role? Can you explain what do you do daily?](https://www.reddit.com/r/cybersecurity/comments/ptdcyr)
**Voice:** Beef_Studpile
**Date as recorded:** September 22 2021 (search-index date)

> Automation simply gives me higher individual capacity to work a given incident

### C259 — Those who are in detection engineering

**Original source:** [Those who are in detection engineering](https://www.reddit.com/r/cybersecurity/comments/1i445jj)
**Voice:** Lanneeh
**Date as recorded:** Page displayed 2y ago; exact date unverified

> After testing and finding eventual gaps, I develop a custom detection, a communication template for our xSOAR and a respective IR procedure

### C260 — Those who are in Detection engineering

**Original source:** [Those who are in Detection engineering](https://www.reddit.com/r/cybersecurity/comments/1t80xyq/those_who_are_in_detection_engineering/)
**Voice:** Present-Guarantee695
**Date as recorded:** Exact publication date not captured

> I work in detection engineering. Wanted to see do other who are working in the same role - do yall …

### C313 — Favorite SOAR Workflows

**Original source:** [Favorite SOAR Workflows](https://www.reddit.com/r/cybersecurity/comments/1hi0whx)
**Voice:** RaiderActual
**Date as recorded:** Page displayed 2y ago; exact date unverified

> Our analysts then take that data and make the final determination.

### C314 — Failed to response to incident

**Original source:** [Failed to response to incident](https://www.reddit.com/r/cybersecurity/comments/1531gbp)
**Voice:** Ratracer56
**Date as recorded:** July 18 2023 (search-index date)

> I am currently managing crowdstrike for a client and If I failed to resolve any incident in 10min then the …

### C328 — Personal favorite SIEM platform?

**Original source:** [Personal favorite SIEM platform?](https://www.reddit.com/r/cybersecurity/comments/1tebfww/personal_favorite_siem_platform/)
**Voice:** rev_mojo
**Date as recorded:** May 15 2026 (search-index date)

> I'm stuck in solo CISO land, so I'm pivoting to an MDR with an MSSP in the middle

### C332 — SIEM Usage

**Original source:** [SIEM Usage](https://www.reddit.com/r/cybersecurity/comments/1lif3y1/siem_usage/)
**Voice:** NoSchool1912
**Date as recorded:** June 23 2025 (search-index date)

> In my country and in the organization where I work, cybersecurity is still a relatively new topic — it has …

### C333 — In your experience, what is the best “modern” SIEM?

**Original source:** [In your experience, what is the best “modern” SIEM?](https://www.reddit.com/r/cybersecurity/comments/1d4ilnn)
**Voice:** Senior-Net-7191
**Date as recorded:** May 31 2024 (search-index date)

> We currently use Splunk ES (which isn’t really a standalone SIEM), but due to recent acquisition, price hikes, and seemingly …

### C334 — On-Prem SIEM?

**Original source:** [On-Prem SIEM?](https://www.reddit.com/r/cybersecurity/comments/1pyrih2/onprem_siem/)
**Voice:** mayday_allday
**Date as recorded:** December 29 2025 (search-index date)

> Can anyone recommend a SIEM software that has many native modules for different systems (like Windows event logs, Linux syslogs, …

### C335 — SIEM integration

**Original source:** [SIEM integration](https://www.reddit.com/r/cybersecurity/comments/1r7r3o0/siem_integration/)
**Voice:** jediairbender
**Date as recorded:** February 18 2026 (search-index date)

> Would like to get everyone’s views on it. What practise are organisations following with respect to onboarding of servers with …

### C336 — What SIEM did you choose and why?

**Original source:** [What SIEM did you choose and why?](https://www.reddit.com/r/cybersecurity/comments/1auzokw)
**Voice:** athanielx
**Date as recorded:** February 19 2024 (search-index date)

> Currently, we're utilizing AlienVault (which is nearing its end-of-life) along with Wazuh as a temporary solution. Our focus is now …

### C338 — What SIEM do you prefer?

**Original source:** [What SIEM do you prefer?](https://www.reddit.com/r/cybersecurity/comments/1llzxbk/what_siem_do_you_prefer/)
**Voice:** alexsious
**Date as recorded:** June 27 2025 (search-index date)

> I have been a sysAdmin for an Operational System for many years. Just changed jobs and am now doing Cyber …

### C340 — Is Google SecOps (Chronicle) a decent SIEM for high-volume environments? (15TB/day, 40+ log sources)

**Original source:** [Is Google SecOps (Chronicle) a decent SIEM for high-volume environments? (15TB/day, 40+ log sources)](https://id.reddit.com/r/cybersecurity/comments/1uag9yh/is_google_secops_chronicle_a_decent_siem_for/)
**Voice:** shahoo7
**Date as recorded:** Exact publication date not captured

> We’re currently evaluating Google SecOps (formerly Chronicle) as a potential SIEM solution and I wanted to get real-world feedback from …

### C343 — How do you generate metrics for threat hunting/intel gathering?

**Original source:** [How do you generate metrics for threat hunting/intel gathering?](https://www.reddit.com/r/cybersecurity/comments/1klro3e)
**Voice:** rtuite81
**Date as recorded:** May 13 2025 (search-index date)

> I'm being asked to account for the time I spend doing things like seeing what vulnerabilities are being leveraged in …

### C346 — Threat hunting from threat intelligence ?

**Original source:** [Threat hunting from threat intelligence ?](https://www.reddit.com/r/cybersecurity/comments/1o2assx/threat_hunting_from_threat_intelligence/)
**Voice:** cantluvorlust
**Date as recorded:** October 09 2025 (search-index date)

> I use defender so I’m able to write a couple basic KQLs myself and edit a few.

### C347 — Biggest challenge you've faced with Threat Hunting?

**Original source:** [Biggest challenge you've faced with Threat Hunting?](https://www.reddit.com/r/cybersecurity/comments/1180bvn)
**Voice:** celleus
**Date as recorded:** February 22 2023 (search-index date)

> We track number of hunts conducted, number of new detection rules created, number of FP reduced

### C350 — Threat hunting?

**Original source:** [Threat hunting?](https://www.reddit.com/r/cybersecurity/comments/1hynt3c)
**Voice:** Brown_Onion9
**Date as recorded:** January 11 2025 (search-index date)

> We don’t do much but when we do it’s not appreciated as some people will oh I know we have …

### C352 — Looking for a threat hunting service on Defender

**Original source:** [Looking for a threat hunting service on Defender](https://www.reddit.com/r/cybersecurity/comments/17rjibj)
**Voice:** Dramatic-Ebb-5796
**Date as recorded:** Page displayed 3y ago; exact date unverified

> But we are struggling to hire experienced threat researchers to keep an eye on the entire infrastructure and call out …

### C358 — SIEM Cost Management Dead End?

**Original source:** [SIEM Cost Management Dead End?](https://www.reddit.com/r/cybersecurity/comments/1mtt63i)
**Voice:** lengmco
**Date as recorded:** August 18 2025 (search-index date)

> On a smaller enterprise “SOC” team (lots of different hats worn) here (a few thousand employee company) and I’m looking …

### C359 — SOC Help

**Original source:** [SOC Help](https://www.reddit.com/r/cybersecurity/comments/1j29jif)
**Voice:** Practical-Violinist9
**Date as recorded:** Page displayed 2y ago; exact date unverified

> Given the amount of data that is ingested every second, how does one go about searching for data that could …

### E06 — Reactive work consumes hunting time

**Original source:** [Reactive work consumes hunting time](https://www.reddit.com/r/Cybersecurity101/comments/1vlc3ef/anyone_else_struggling_to_get_proactive_threat/)
**Voice:** Ok-Parfait2480
**Date as recorded:** 2026-08-11 in search result; cached relative age varied

> As soon as the alert queue spikes or a real incident starts, threat hunting is the first activity that gets dropped.

### E07 — SOC builders cannot tell what they fail to detect

**Original source:** [SOC builders cannot tell what they fail to detect](https://www.reddit.com/r/blueteamsec/comments/1tm5gbo/built_a_soc_from_scratch_with_no_prior_soc/)
**Voice:** After_Marsupial_3531
**Date as recorded:** 2026-05-24 in search result

> it didn't give me a clear sense of what I'm actually missing on the detection side

### E18 — Data-lake migration does not remove enrichment work

**Original source:** [Data-lake migration does not remove enrichment work](https://www.reddit.com/r/blueteamsec/comments/17lqx19/detection_engineering/)
**Voice:** SignificantShame430
**Date as recorded:** 2023-11-02

> My worry is dirty data and not effectively “enriching” the data to provide enough value.

### C022 — Most SOC alerts are noise because we don't baseline properly. Here's what actually changed when I started doing it right

**Original source:** [Most SOC alerts are noise because we don't baseline properly. Here's what actually changed when I started doing it right](https://www.reddit.com/r/blueteamsec/comments/1s6irc7/most_soc_alerts_are_noise_because_we_dont/)
**Voice:** PIKxu
**Date as recorded:** March 29 2026 (search-index date)

> I've been running queries in production Sentinel for some months, and the biggest realization was that there is no magic …

### C023 — How do you actually validate detection coverage?

**Original source:** [How do you actually validate detection coverage?](https://www.reddit.com/r/blueteamsec/comments/1svgwy8/how_do_you_actually_validate_detection_coverage/)
**Voice:** PhantomArmorSec
**Date as recorded:** April 25 2026 (search-index date)

> Quick question for folks doing detection work:

### C026 — How are you keeping up with IOCs for detection rules?

**Original source:** [How are you keeping up with IOCs for detection rules?](https://www.reddit.com/r/blueteamsec/comments/1m9bf80)
**Voice:** ApprehensiveOlive353
**Date as recorded:** July 25 2025 (search-index date)

> Manual conversion of emerging threat IOCs into detection rules (Sigma, YARA, etc.) is killing me. It's too slow, threats move …

### C027 — Looking for resources on end-to-end APT attack flow summaries for detection engineering

**Original source:** [Looking for resources on end-to-end APT attack flow summaries for detection engineering](https://www.reddit.com/r/blueteamsec/comments/1tpf9uk/looking_for_resources_on_endtoend_apt_attack_flow/)
**Voice:** Ornery-Impress2725
**Date as recorded:** May 27 2026 (search-index date)

> I’m currently focusing on improving our detection engineering and threat hunting capabilities by moving beyond just IoCs and looking closer …

### C256 — Blue Teamers: What makes a good detection use case?

**Original source:** [Blue Teamers: What makes a good detection use case?](https://www.reddit.com/r/blueteamsec/comments/zrrew1)
**Voice:** hooper359
**Date as recorded:** December 21 2022 (search-index date)

> I've been trying to deal with some alert overload issues our SOC has been having and putting a priority on …

### C258 — Detection Analyst/Detection Engineering

**Original source:** [Detection Analyst/Detection Engineering](https://www.reddit.com/r/blueteamsec/comments/fn6ehe)
**Voice:** capr1
**Date as recorded:** March 22 2020 (search-index date)

> I work at a large company. We had a big incident an year ago and our CISO has ramped up …

### C353 — Log Export from SIEM

**Original source:** [Log Export from SIEM](https://www.reddit.com/r/blueteamsec/comments/1v9nrv1/log_export_from_siem/)
**Voice:** dutchhboii
**Date as recorded:** July 29 2026 (search-index date)

> We’re dealing with millions of logs, and the requirement is to export them to their secure platform, which only they …

### E09 — Customers need action and a clear contact path

**Original source:** [Customers need action and a clear contact path](https://www.reddit.com/r/msp/comments/1kihf64/yet_another_soc_thread_siemfull_service/)
**Voice:** IT_Hero
**Date as recorded:** 2025-05-09 in search result

> they'd prefer the SOC to reach out directly to them for the actionable items rather than go through the MSP.

### C032 — Managed SOC solutions for MSPs?

**Original source:** [Managed SOC solutions for MSPs?](https://www.reddit.com/r/msp/comments/1d7x321/managed_soc_solutions_for_msps/)
**Voice:** Izual_Rebirth
**Date as recorded:** June 05 2024 (search-index date)

> Tried Cyrebro before but wasn’t impressed with how quick they were so currently in the lookout. This is for SME …

### C033 — SIEM/SOC/MDR in 2026

**Original source:** [SIEM/SOC/MDR in 2026](https://www.reddit.com/r/msp/comments/1vuif8s/siemsocmdr_in_2026/)
**Voice:** sman200788
**Date as recorded:** August 21 2026 (search-index date)

> Biggest reason is 24/7 monitoring and taking workload off of our already incredibly busy staff. We have been looking at …

### C101 — Took over from another MSP, immediately found security threat.

**Original source:** [Took over from another MSP, immediately found security threat.](https://www.reddit.com/r/msp/comments/1uyylys/took_over_from_another_msp_immediately_found/)
**Voice:** terselated
**Date as recorded:** July 17 2026 (search-index date)

> I have a local competitor who offices right down the street from our office. Bigger MSP than us, fairly mature, …

### C102 — Huntress MDR for 365

**Original source:** [Huntress MDR for 365](https://www.reddit.com/r/msp/comments/189m1ml/huntress_mdr_for_365/)
**Voice:** tasdotgray
**Date as recorded:** December 03 2023 (search-index date)

> In that time, 3 accounts were compromised and huntress only detected 1. Each one was flagged by Entra as a …

### C103 — Office 365 MDR Solutions

**Original source:** [Office 365 MDR Solutions](https://www.reddit.com/r/msp/comments/1iaqhk1)
**Voice:** Few_Juggernaut5107
**Date as recorded:** January 26 2025 (search-index date)

> We've recently had an issue with what appears to be token hijacking, the outcome was sent email from internal users …

### C105 — MSP's that offer a SOC solution - how did it affect your ticket count and support costs?

**Original source:** [MSP's that offer a SOC solution - how did it affect your ticket count and support costs?](https://www.reddit.com/r/msp/comments/1alu1ee)
**Voice:** MSP911
**Date as recorded:** February 09 2024 (search-index date)

> The SOC provider obviously does triage on everything but there is still noise that we or the client will need …

### C106 — N-Able MDR and ITDR (Adlumin) Feedback

**Original source:** [N-Able MDR and ITDR (Adlumin) Feedback](https://www.reddit.com/r/msp/comments/1peipds/nable_mdr_and_itdr_adlumin_feedback/)
**Voice:** lurkinmsp
**Date as recorded:** December 06 2025 (search-index date)

> I'm currently looking into a lot of options for MDR. If you look at my post history you'll see recently …

### C107 — ITDR Frustrations

**Original source:** [ITDR Frustrations](https://www.reddit.com/r/msp/comments/1pv5h59/itdr_frustrations/)
**Voice:** DeathTropper69
**Date as recorded:** Exact publication date not captured

> Anyone else running into frustration with ITDR? Like I get the point of it, but it just feels so much …

### C109 — Blackpoint Delayed Cloud Responses

**Original source:** [Blackpoint Delayed Cloud Responses](https://www.reddit.com/r/msp/comments/1e6wlpi)
**Voice:** cory906
**Date as recorded:** Page displayed 2y ago; exact date unverified

> I've had 2 successful phishing attempts on a client this month and both incidents were concerning in regards to Blackpoint. …

### C185 — How do other MSPs efficiently handle security alerts?

**Original source:** [How do other MSPs efficiently handle security alerts?](https://www.reddit.com/r/msp/comments/1j9lyv1)
**Voice:** Roya11ty
**Date as recorded:** March 12 2025 (search-index date)

> Right now, all our security alerts come into our ITSM system, and every alert requires manual intervention, which can be …

### C188 — Defender detecting N-Central software-scanner.exe as malware

**Original source:** [Defender detecting N-Central software-scanner.exe as malware](https://www.reddit.com/r/msp/comments/1q1jdjg/defender_detecting_ncentral_softwarescannerexe_as/)
**Voice:** no_regerts_bob
**Date as recorded:** January 02 2026 (search-index date)

> I just started getting alerts on PCs where we have defender for endpoint and N-Central RMM installed. Anyone else seeing …

### C189 — 24x7 SoC for MSP

**Original source:** [24x7 SoC for MSP](https://www.reddit.com/r/msp/comments/1isa2qt)
**Voice:** TerryLewisUK
**Date as recorded:** February 19 2025 (search-index date)

> People seem to get really good responses from Huntress and Crowdstrike on the more MDR side of things. But can …

### C190 — SIEM for MSP

**Original source:** [SIEM for MSP](https://www.reddit.com/r/msp/comments/g8mgh8)
**Voice:** TechFiend72
**Date as recorded:** April 26 2020 (search-index date)

> I just joined an MSP and found out they don't have a SIEM solution for their clients.

### C266 — Customer security baselines

**Original source:** [Customer security baselines](https://www.reddit.com/r/msp/comments/uu3wtp)
**Voice:** [deleted]
**Date as recorded:** May 20 2022 (search-index date)

> Yesterday I made a comment about some security baselines we use with our customers. This list is fairly sanitized, where …

### C267 — Huntress and Event Log Analysis

**Original source:** [Huntress and Event Log Analysis](https://www.reddit.com/r/msp/comments/1exb2eu)
**Voice:** BornConcentrate5571
**Date as recorded:** August 20 2024 (search-index date)

> Recently we had a client experience an attempted brute force attack on their Windows server which we noticed. Turns out …

### C268 — SIEMaaS or SIEMaaS\SOC

**Original source:** [SIEMaaS or SIEMaaS\SOC](https://www.reddit.com/r/msp/comments/chgvhj)
**Voice:** gpshift
**Date as recorded:** July 25 2019 (search-index date)

> The main thing it's missing that I would like to have are compliance based reports.

### C269 — Does anyone have a recommendation for a good all in one security package and SOC?

**Original source:** [Does anyone have a recommendation for a good all in one security package and SOC?](https://www.reddit.com/r/msp/comments/1oatt31/does_anyone_have_a_recommendation_for_a_good_all/)
**Voice:** Paradox_81
**Date as recorded:** October 19 2025 (search-index date)

> There seems to be so many offerings these days that link to various platforms with APIs and GDAP for 365 …

### C270 — Boss wants me to add a SOC to our MSP

**Original source:** [Boss wants me to add a SOC to our MSP](https://www.reddit.com/r/msp/comments/f14pwf)
**Voice:** Incrediblecodeman
**Date as recorded:** February 10 2020 (search-index date)

> Currently there is little security culture, We are in the security audit planning phase:

### C273 — Which Soc to use

**Original source:** [Which Soc to use](https://www.reddit.com/r/msp/comments/16c5jaq)
**Voice:** 7FootElvis
**Date as recorded:** September 07 2023 (search-index date)

> These guys got on a 3HR call with us and engaged the security endpoint's SOC as needed

### C360 — How high are you siem infrascture costs?

**Original source:** [How high are you siem infrascture costs?](https://www.reddit.com/r/msp/comments/1kzh7tn)
**Voice:** Doctorphate
**Date as recorded:** Page displayed 1y ago; exact date unverified

> Storage is pretty cheap, biggest cost is labour which is primarily mine.

### C361 — Client facing reporting options?

**Original source:** [Client facing reporting options?](https://www.reddit.com/r/msp/comments/1j12wrr)
**Voice:** MSP-from-OC
**Date as recorded:** March 01 2025 (search-index date)

> I think we are at the place where we need better client facing reports on what we are doing for …

### E10 — An alert does not lead directly to its evidence

**Original source:** [An alert does not lead directly to its evidence](https://discuss.elastic.co/t/multiple-alerts-in-different-att-ck-tactics-on-a-single-host/379248)
**Voice:** GKre
**Date as recorded:** 2025-06-17 to 2025-06-18; forum timestamps

> How can i get the events that triggered this alert?

### E11 — Case timestamps cannot answer an SLA question

**Original source:** [Case timestamps cannot answer an SLA question](https://discuss.elastic.co/t/alert-response-action-sla-support/379333)
**Voice:** taylor.callow (Taylor)
**Date as recorded:** 2025-06-19; forum timestamp

> timestamp alert is set to acknowledged

### E12 — AI analysis scope can be opaque

**Original source:** [AI analysis scope can be opaque](https://discuss.elastic.co/t/attack-discovery-questions-and-feedback/364109)
**Voice:** willemdh (WillemDH)
**Date as recorded:** 2024-07-31; forum timestamp; Elastic 8.14.3

> Other time I saw it choose 10 identical alerts.

### C040 — Elastic Security field values in connector getting duplicated

**Original source:** [Elastic Security field values in connector getting duplicated](https://discuss.elastic.co/t/elastic-security-field-values-in-connector-getting-duplicated/313725)
**Voice:** RaonyO (Raony Oliveira)
**Date as recorded:** September 6, 2022

> and the rule detects it normally, but in the action part the events are going with duplicate fields. for example: …

### C041 — Security Alert ：How to suppress repeat alarms

**Original source:** [Security Alert ：How to suppress repeat alarms](https://discuss.elastic.co/t/security-alert-how-to-suppress-repeat-alarms/325565)
**Voice:** xqaiviwjxzw (xqaiviwjxzw)
**Date as recorded:** February 15, 2023

> More than 100 duplicate alarms are generated in 1 minute, what can be done to suppress duplicate alarms and display …

### C042 — **Only some alerts are triggered during scheduled execution.**

**Original source:** [**Only some alerts are triggered during scheduled execution.**](https://discuss.elastic.co/t/only-some-alerts-are-triggered-during-scheduled-execution/379037)
**Voice:** Kick
**Date as recorded:** June 10, 2025

> While manual execution detects all matching logs without any issue, scheduled execution fails to detect some of them.

### C043 — EQL rules do not work but see hits

**Original source:** [EQL rules do not work but see hits](https://discuss.elastic.co/t/eql-rules-do-not-work-but-see-hits/297136)
**Voice:** Why
**Date as recorded:** February 14, 2022

> I'm trying to get started with Elastic SIEM and I noticed a problem.

### C044 — 27 default Elastic Security rules contain definitions to non-existant indices and are broken

**Original source:** [27 default Elastic Security rules contain definitions to non-existant indices and are broken](https://discuss.elastic.co/t/27-default-elastic-security-rules-contain-definitions-to-non-existant-indices-and-are-broken/303043)
**Voice:** finbarr996 (John Douglas)
**Date as recorded:** April 22, 2022

> As an example, the Elastic supplied default 'Endpoint Security' rule contains a hard coded definition to the index pattern 'logs-endpoint.alerts-*' …

### C045 — Alert Suppression on Event Correlation Rule (duplicate alerts)

**Original source:** [Alert Suppression on Event Correlation Rule (duplicate alerts)](https://discuss.elastic.co/t/alert-suppression-on-event-correlation-rule-duplicate-alerts/338837)
**Voice:** adub08 (Alex Woodmansey)
**Date as recorded:** July 20, 2023

> Has anyone found a good way of modifying the prebuilt in event coloration rules Elastic Security to not produce too …

### C046 — How to duplicate a rule?

**Original source:** [How to duplicate a rule?](https://discuss.elastic.co/t/how-to-duplicate-a-rule/331042)
**Voice:** ppic (Paul Picard)
**Date as recorded:** April 28, 2023

> I have to create several rules-alerts that are very similar.

### C047 — Reduce duplicate signals/ alerts

**Original source:** [Reduce duplicate signals/ alerts](https://discuss.elastic.co/t/reduce-duplicate-signals-alerts/282768)
**Voice:** jaspher
**Date as recorded:** August 29, 2021

> Is it possible to mute/ ignore repeating alerts for a period of time?

### C048 — How to split data into spaces

**Original source:** [How to split data into spaces](https://discuss.elastic.co/t/how-to-split-data-into-spaces/330229)
**Voice:** Joelgoncalves3000 (Teste Elastic)
**Date as recorded:** April 18, 2023

> Hello, let's imagine that I have a cluster with 5 nodes and each node is a client, I want these …

### C049 — Single behavior generates several alerts

**Original source:** [Single behavior generates several alerts](https://discuss.elastic.co/t/single-behavior-generates-several-alerts/283943)
**Voice:** frank_rib
**Date as recorded:** September 11, 2021

> I have a lot of alerts generated by a single behavior scan from the address IP x.x.x.x to the ip …

### C050 — Sort/Toggle Detection Rules by Severity or Risk Score

**Original source:** [Sort/Toggle Detection Rules by Severity or Risk Score](https://discuss.elastic.co/t/sort-toggle-detection-rules-by-severity-or-risk-score/276064)
**Voice:** scanlan
**Date as recorded:** June 16, 2021

> Is it possible to sort detection rules by risk score or severity?

### C112 — Timeline Template see fields other then the fields in the alert

**Original source:** [Timeline Template see fields other then the fields in the alert](https://discuss.elastic.co/t/timeline-template-see-fields-other-then-the-fields-in-the-alert/352756)
**Voice:** RoeeKent
**Date as recorded:** February 7, 2024

> I would love to know if it is possible to add a timeline template to a detection rule, and use …

### C113 — Timeline template change timefilter to @timestamp instead of event.ingested?

**Original source:** [Timeline template change timefilter to @timestamp instead of event.ingested?](https://discuss.elastic.co/t/timeline-template-change-timefilter-to-timestamp-instead-of-event-ingested/333087)
**Voice:** elk_jh
**Date as recorded:** May 10, 2023

> Our logs has a lag during ingestion where the event.ingested is behind the original timestamp by 10mins or so. When …

### C114 — Anyone have success using Machine Learning to detect Fast or Impossible Travel?

**Original source:** [Anyone have success using Machine Learning to detect Fast or Impossible Travel?](https://discuss.elastic.co/t/anyone-have-success-using-machine-learning-to-detect-fast-or-impossible-travel/288822)
**Voice:** obsidian
**Date as recorded:** November 9, 2021

> So far I've seen a built-in job called rare source ip for user, however, it is using auditbeat. Is there …

### C116 — Creating cases from signals

**Original source:** [Creating cases from signals](https://discuss.elastic.co/t/creating-cases-from-signals/238315)
**Voice:** forkhead (Forkhead)
**Date as recorded:** June 23, 2020

> Hi, I am trying to understand a couple of things with Detections and Cases in Elastic SIEM -

### C118 — Timeline Template not applied when Alert fires

**Original source:** [Timeline Template not applied when Alert fires](https://discuss.elastic.co/t/timeline-template-not-applied-when-alert-fires/301950)
**Voice:** PhilA (Phil)
**Date as recorded:** April 8, 2022

> I am having issues with timeline templates. I have built a custom template showing some specific fields I would be …

### C119 — Customize SIEM Detection columns based on alert

**Original source:** [Customize SIEM Detection columns based on alert](https://discuss.elastic.co/t/customize-siem-detection-columns-based-on-alert/263228)
**Voice:** madduck
**Date as recorded:** February 4, 2021

> it seems like the Columns in the SIEM Application are more or less static and if I want a new …

### C121 — Many open alarms (building blocks) due to Correlation rules

**Original source:** [Many open alarms (building blocks) due to Correlation rules](https://discuss.elastic.co/t/many-open-alarms-building-blocks-due-to-correlation-rules/345014)
**Voice:** siiman
**Date as recorded:** October 13, 2023

> This results in a large number of unnoticed open alerts.

### C123 — Threat Hunting Report for Elasticsearch

**Original source:** [Threat Hunting Report for Elasticsearch](https://discuss.elastic.co/t/threat-hunting-report-for-elasticsearch/246540)
**Voice:** syafeera (nursyafeera)
**Date as recorded:** August 27, 2020

> Did anyone here know how to do Threat Hunting report using SIEM in Kibana?

### C193 — SIEM created and closed cases report

**Original source:** [SIEM created and closed cases report](https://discuss.elastic.co/t/siem-created-and-closed-cases-report/270931)
**Voice:** bnk (Ema)
**Date as recorded:** April 22, 2021

> Hello, I looked information if there is a possibility to export info about created and closed cases (also tags associated …

### C195 — Use case question: Support for reporting to third party

**Original source:** [Use case question: Support for reporting to third party](https://discuss.elastic.co/t/use-case-question-support-for-reporting-to-third-party/252681)
**Voice:** Thremore (Markus)
**Date as recorded:** October 20, 2020

> Hello! Complete noob here. Thank you for your patience over my ignorance.

### C196 — How to track cases in a dashboard? - #2 by christos.nasikas

**Original source:** [How to track cases in a dashboard? - #2 by christos.nasikas](https://discuss.elastic.co/t/how-to-track-cases-in-a-dashboard/287259/2)
**Voice:** elasticfran (fran)
**Date as recorded:** October 21, 2021

> but i happen not to have the option "add a les" visualization.

### C275 — Alerting when data stops coming in from variety of sources - #3 by leandrojmp

**Original source:** [Alerting when data stops coming in from variety of sources - #3 by leandrojmp](https://discuss.elastic.co/t/alerting-when-data-stops-coming-in-from-variety-of-sources/379787/3)
**Voice:** erikg
**Date as recorded:** July 3, 2025

> I normally used an index threshold rule to notify me if an index reaches 0 documents. But now with this …

### C276 — Alerts ceased to be generated

**Original source:** [Alerts ceased to be generated](https://discuss.elastic.co/t/alerts-ceased-to-be-generated/280671)
**Voice:** frank_rib
**Date as recorded:** August 6, 2021

> The alerts have ceased to be generated today at the detection level, after checking I noticed that the rules are …

### C277 — Custom detection rules failing in bulk

**Original source:** [Custom detection rules failing in bulk](https://discuss.elastic.co/t/custom-detection-rules-failing-in-bulk/265376)
**Voice:** jhanvi (JJ)
**Date as recorded:** February 24, 2021

> In the detection tab, I am observing that the rules are failing and throwing an error as below. Can you …

### C278 — Endpoint Security help

**Original source:** [Endpoint Security help](https://discuss.elastic.co/t/endpoint-security-help/305463)
**Voice:** insurin (insurin)
**Date as recorded:** May 24, 2022

> I can see my hosts under /Security/Endpoints but I am not getting any activity.

### C280 — Elastic Detections permissions issues

**Original source:** [Elastic Detections permissions issues](https://discuss.elastic.co/t/elastic-detections-permissions-issues/257751)
**Voice:** yarooski
**Date as recorded:** December 5, 2020

> I created a role with all the required permissions according to the documentation and assigned it to my user, but …

### C282 — Brute Force Detection Rule

**Original source:** [Brute Force Detection Rule](https://discuss.elastic.co/t/brute-force-detection-rule/271713)
**Voice:** filip.wozniak
**Date as recorded:** April 29, 2021

> I want to write my own rule: If any user in last 5 minutes failed to login 5 times, Detection …

### C283 — Host isolation permission issue

**Original source:** [Host isolation permission issue](https://discuss.elastic.co/t/host-isolation-permission-issue/350492)
**Voice:** nmurilo (Nelson Murilo)
**Date as recorded:** January 5, 2024

> I’m trying to grant host isolate perms configuring the "Role Mappings" but without success. Tried the same configuration steps (same …

### C369 — Issue with connecting to local llm from 8.18.0 ESv

**Original source:** [Issue with connecting to local llm from 8.18.0 ESv](https://discuss.elastic.co/t/issue-with-connecting-to-local-llm-from-8-18-0-esv/380086)
**Voice:** Abhi_Abhishek (Abhi Abhishek)
**Date as recorded:** July 14, 2025

> We are facing issues with connecting to our local LLM from Elasticsearch cluster of 8.18.0 version. While we are able …

### C370 — Questions about OpenAI connectors

**Original source:** [Questions about OpenAI connectors](https://discuss.elastic.co/t/questions-about-openai-connectors/381367)
**Voice:** willemdh (WillemDH)
**Date as recorded:** August 27, 2025

> Today I was playing with OpenAI connector settings in Elastic Security Serverless and I have some questions for which I …

### C374 — How to include field data from multiple documents in `Create a model response` API request?

**Original source:** [How to include field data from multiple documents in `Create a model response` API request?](https://discuss.elastic.co/t/how-to-include-field-data-from-multiple-documents-in-create-a-model-response-api-request/382129)
**Voice:** logalicious
**Date as recorded:** September 22, 2025

> When I include multiple messages that each contain field data from security alerts, the Security AI assistant only provides a …

### E13 — A case stays open in one console after closing elsewhere

**Original source:** [A case stays open in one console after closing elsewhere](https://techcommunity.microsoft.com/discussions/microsoftdefendercloud/duplicate-alerts-in-defender-for-cloud-from-mde/4360211)
**Voice:** packetknight
**Date as recorded:** 2024-12-23 original post; 2025-01-12 is a reply date

> its status is not being synced.

### E39 — A previously working connector stops delivering logs

**Original source:** [A previously working connector stops delivering logs](https://techcommunity.microsoft.com/discussions/microsoftsentinel/trend-micro-vision-one-connector-not-working/4434918)
**Voice:** mal_sec
**Date as recorded:** 2025-07-21

> the logs stopped ingesting.

### E40 — A query returns no results under the expected time filter

**Original source:** [A query returns no results under the expected time filter](https://techcommunity.microsoft.com/discussions/microsoftthreatprotection/unable-to-query-logs-in-advanced-hunting/4433733)
**Voice:** akshayp199503
**Date as recorded:** 2025-07-16

> The above yields no results in AdvancedHunting pane.

### C051 — Logic app returns empty array trying list alarms related to Sentinel incident

**Original source:** [Logic app returns empty array trying list alarms related to Sentinel incident](https://techcommunity.microsoft.com/discussions/microsoftsentinel/logic-app-returns-empty-array-trying-list-alarms-related-to-sentinel-incident/3927047)
**Voice:** imelekhin
**Date as recorded:** Sep 13, 2023

> Problem is that Azure Monitor logs connector always return empty output array.

### C052 — Sentinel Playbook with incident trigger issue

**Original source:** [Sentinel Playbook with incident trigger issue](https://techcommunity.microsoft.com/discussions/microsoftsentinel/sentinel-playbook-with-incident-trigger-issue/3758695/)
**Voice:** rudite460
**Date as recorded:** Mar 03, 2023

> I have a set of playbooks to run automatically when an incident is created - using "When Azure Sentinel incident …

### C053 — defender incidents are automatically re-opening

**Original source:** [defender incidents are automatically re-opening](https://techcommunity.microsoft.com/discussions/microsoftthreatprotection/defender-incidents-are-automatically-re-opening/3576367/replies/3580165)
**Voice:** NCreminder
**Date as recorded:** Jul 19, 2022

> defender incidents are automatically changing the status from Resolved to Active.

### C054 — The Hidden Reason Your Sentinel Playbook Won't Show Up in Automation Rules (It's Not RBAC)

**Original source:** [The Hidden Reason Your Sentinel Playbook Won't Show Up in Automation Rules (It's Not RBAC)](https://techcommunity.microsoft.com/discussions/microsoftsentinel/the-hidden-reason-your-sentinel-playbook-wont-show-up-in-automation-rules-its-no/4555416)
**Voice:** Blackfoundry
**Date as recorded:** Sep 10, 2026

> > If a Logic App using the native Microsoft Sentinel incident trigger doesn't show up in the "Run playbook" picker …

### C055 — Entities missing in Incidents

**Original source:** [Entities missing in Incidents](https://techcommunity.microsoft.com/discussions/microsoftsentinel/entities-missing-in-incidents/3920866)
**Voice:** Sidra_Raza
**Date as recorded:** Sep 07, 2023

> Entities are not showing on any of the incidents in Sentinel. Although, I have mapped the entities correctly for each …

### C057 — Failed to trigger playbook - Error

**Original source:** [Failed to trigger playbook - Error](https://techcommunity.microsoft.com/discussions/microsoftsentinel/failed-to-trigger-playbook---error/3902333)
**Voice:** Usama_Saleem
**Date as recorded:** Aug 17, 2023

> It requires a re sign in after assigning the specific permission.

### C058 — Can't add playbook to incident automation of an analytics rule.

**Original source:** [Can't add playbook to incident automation of an analytics rule.](https://techcommunity.microsoft.com/discussions/microsoftsentinel/cant-add-playbook-to-incident-automation-of-an-analytics-rule-/2857311/replies/2860369)
**Voice:** basc0
**Date as recorded:** Oct 18, 2021

> The playbooks won't be added to the rule.

### C059 — Multi-trigger Playbooks & Renamed Triggers

**Original source:** [Multi-trigger Playbooks & Renamed Triggers](https://techcommunity.microsoft.com/discussions/microsoftsentinel/multi-trigger-playbooks--renamed-triggers/4427880)
**Voice:** sebagius
**Date as recorded:** Jun 27, 2025

> In some cases, deploying a playbook with multiple triggers is a much easier solution than having 9 playbooks which do …

### C060 — Microsoft re-opening and re-closing Incidents in Sentinel

**Original source:** [Microsoft re-opening and re-closing Incidents in Sentinel](https://techcommunity.microsoft.com/discussions/microsoftsentinel/microsoft-re-opening-and-re-closing-incidents-in-sentinel/3619400/replies/3624356)
**Voice:** ElisabethSN
**Date as recorded:** Sep 07, 2022

> Hey, so we have experienced several times MS re-opening incidents in Sentinel that one of our analysts have already closed. …

### C124 — Alerting when data are missing

**Original source:** [Alerting when data are missing](https://techcommunity.microsoft.com/discussions/microsoftsentinel/alerting-when-data-are-missing/3595737/replies/3596407)
**Voice:** T150732D
**Date as recorded:** Aug 10, 2022

> I would like to have incident if there is a gap in ingested data

### C125 — Estimating Sentinel Costs

**Original source:** [Estimating Sentinel Costs](https://techcommunity.microsoft.com/discussions/microsoftsentinel/estimating-sentinel-costs/2351416/)
**Voice:** Andrew Cliff
**Date as recorded:** May 13, 2021

> We're looking to estimate potential costs for Azure Sentinel but the pricing is very confusing (at least to me).

### C126 — Sophos Endpoint Protection Log Ingestion Issue

**Original source:** [Sophos Endpoint Protection Log Ingestion Issue](https://techcommunity.microsoft.com/discussions/microsoftsentinel/sophos-endpoint-protection-log-ingestion-issue/3898818)
**Voice:** Usama_Saleem
**Date as recorded:** Aug 14, 2023

> It only ingested logs at the time when the connector was connected

### C127 — Issue when ingesting Defender XDR table in Sentinel

**Original source:** [Issue when ingesting Defender XDR table in Sentinel](https://techcommunity.microsoft.com/discussions/microsoftsentinel/issue-when-ingesting-defender-xdr-table-in-sentinel/4463990/replies/4482416)
**Voice:** lsoumille
**Date as recorded:** Oct 24, 2025

> We are migrating our on-premises SIEM solution to Microsoft Sentinel since we have E5 licences for all our users. The …

### C128 — Palo Alto Global Protect Logs Missing Most information

**Original source:** [Palo Alto Global Protect Logs Missing Most information](https://techcommunity.microsoft.com/discussions/microsoftsentinel/palo-alto-global-protect-logs-missing-most-information/4156713/replies/4362356)
**Voice:** HA13029
**Date as recorded:** May 30, 2024

> But for GlobalProtect log type, it's missing almost all valuable values (no username, authentication status (failed or success), Portal Name, …

### C129 — Delay in Azure Sentinel scheduled alerts

**Original source:** [Delay in Azure Sentinel scheduled alerts](https://techcommunity.microsoft.com/t5/azure-sentinel/delay-in-azure-sentinel-scheduled-alerts/m-p/2596337)
**Voice:** zubairrahimsoc
**Date as recorded:** Jul 30, 2021

> Sometimes its very delay to receive the alerts of the Schedule rules of Kaspersky. While the query runs every 5 …

### C130 — Controlling visability and ingestion of custom logs

**Original source:** [Controlling visability and ingestion of custom logs](https://techcommunity.microsoft.com/discussions/microsoftsentinel/controlling-visability-and-ingestion-of-custom-logs/1097784)
**Voice:** securityninja
**Date as recorded:** Jan 08, 2020

> I've just been asked to look at the MS LA/Sentinel stack. I have a decent background in another popular log …

### C132 — Ingest CEF logs in CommonSecurityLog with Logstasth

**Original source:** [Ingest CEF logs in CommonSecurityLog with Logstasth](https://techcommunity.microsoft.com/discussions/microsoftsentinel/ingest-cef-logs-in-commonsecuritylog-with-logstasth/3984121)
**Voice:** vincenthoag
**Date as recorded:** Nov 15, 2023

> The reason behind Logstash choice is that AMA only has a 10 GB buffer size which is too small for …

### C133 — Bi-directional sync missing in Defender for Cloud (Tenant-Based) connector in Sentinel?

**Original source:** [Bi-directional sync missing in Defender for Cloud (Tenant-Based) connector in Sentinel?](https://techcommunity.microsoft.com/discussions/communityquestions/bi-directional-sync-missing-in-defender-for-cloud-tenant-based-connector-in-sent/4430564/)
**Voice:** Lucifier0786
**Date as recorded:** Jul 06, 2025

> We enabled the Defender for Cloud (Tenant-Based) connector in Microsoft Sentinel, and according to recent updates, it should now support …

### C204 — Create a report that contains Alerts and raw events

**Original source:** [Create a report that contains Alerts and raw events](https://techcommunity.microsoft.com/discussions/microsoftsentinel/create-a-report-that-contains-alerts-and-raw-events/4377809)
**Voice:** Zorghost
**Date as recorded:** Feb 12, 2025

> is there a way to autoamtically create a report in sentinel that contains security incidents and alerts as well as …

### C205 — Include Additional Entities Detail in Email

**Original source:** [Include Additional Entities Detail in Email](https://techcommunity.microsoft.com/discussions/microsoftsentinel/include-additional-entities-detail-in-email/3942354)
**Voice:** DGMalcolm
**Date as recorded:** Sep 29, 2023

> I am receiving the emails when incidents happen but the emails are missing some important details. For example, I occasionally …

### C206 — It sure would be nice for Sentinel to report what user accounts generated Alerts

**Original source:** [It sure would be nice for Sentinel to report what user accounts generated Alerts](https://techcommunity.microsoft.com/discussions/microsoft-security/it-sure-would-be-nice-for-sentinel-to-report-what-user-accounts-generated-alerts/1275519/)
**Voice:** jsebast1245
**Date as recorded:** Apr 02, 2020

> If I open any of these, there is no information on what user generated the issue or what file was …

### C207 — Enrich Sentinel Incident Emails

**Original source:** [Enrich Sentinel Incident Emails](https://techcommunity.microsoft.com/discussions/microsoftsentinel/enrich-sentinel-incident-emails/4045152)
**Voice:** DGMalcolm
**Date as recorded:** Jan 31, 2024

> I've posted here on this topic before when I didn't even know where to start - (https://techcommunity.microsoft.com/t5/microsoft-sentinel/include-additional-entities-detail-in-email/m-p/3942354 ). The guidance …

### C208 — API Power BI Report

**Original source:** [API Power BI Report](https://techcommunity.microsoft.com/discussions/microsoftsentinel/api-power-bi-report/3198005/)
**Voice:** CanerHan
**Date as recorded:** Feb 22, 2022

> i have to build a Power BI Report. I need all incidents and their alerts from Sentinel.

### C209 — Automate Incident Timeline Into Report

**Original source:** [Automate Incident Timeline Into Report](https://techcommunity.microsoft.com/discussions/microsoftsentinel/automate-incident-timeline-into-report/3608531)
**Voice:** Smittydude8822
**Date as recorded:** Aug 24, 2022

> We are looking to automate as much as possible within Sentinel, which we are hoping can include some of our …

### C210 — How to get the real count of incidents in Microsoft Sentinel?

**Original source:** [How to get the real count of incidents in Microsoft Sentinel?](https://techcommunity.microsoft.com/discussions/microsoftsentinel/how-to-get-the-real-count-of-incidents-in-microsoft-sentinel/3102751/replies/3103991)
**Voice:** zaylinhtun
**Date as recorded:** Feb 01, 2022

> Hi guys, when I do the monthly report for my customers, I found different counts of security incidents. I can …

### C211 — Simplest way to get email notifications for Analytics Rules

**Original source:** [Simplest way to get email notifications for Analytics Rules](https://techcommunity.microsoft.com/discussions/microsoftsentinel/simplest-way-to-get-email-notifications-for-analytics-rules/2958947/replies/4045005)
**Voice:** DGMalcolm
**Date as recorded:** Nov 12, 2021

> Taking over for a recent employee departure and totally new to the Azure Sentinel space. A couple years of Azure …

### C212 — Azure Sentinel - Scheduled Search

**Original source:** [Azure Sentinel - Scheduled Search](https://techcommunity.microsoft.com/discussions/azureobservability/azure-sentinel---scheduled-search/2073735)
**Voice:** Yasta190
**Date as recorded:** Jan 19, 2021

> I need to create a report on Azure Sentinel that will send its results to selected group of email addresses, …

### C286 — Multiple M365 tenants in sentinel

**Original source:** [Multiple M365 tenants in sentinel](https://techcommunity.microsoft.com/discussions/microsoftsentinel/multiple-m365-tenants-in-sentinel/2350384/)
**Voice:** kinomakino
**Date as recorded:** May 13, 2021

> Can you think of a way to manage multiple M365 subscriptions in the same Sentinel?

### C287 — Sentinel across multiple environments

**Original source:** [Sentinel across multiple environments](https://techcommunity.microsoft.com/discussions/microsoftsentinel/sentinel-across-multiple-environments/2274229/)
**Voice:** a8ree
**Date as recorded:** Apr 15, 2021

> We are currently planning a new Azure presence. Each of our environments is distinct (Prod/Pre-Prod/Non-Prod) within different subscriptions with each …

### C288 — MSSP multi-tenant with Microsoft sentinel

**Original source:** [MSSP multi-tenant with Microsoft sentinel](https://techcommunity.microsoft.com/discussions/microsoftsentinel/mssp-multi-tenant-with-microsoft-sentinel/3471024/replies/3474868)
**Voice:** Qusai_Ismail
**Date as recorded:** Jun 06, 2022

> We are trying to find a full documentation of how to connect our sentinel project to different subscription workspace, each …

### C293 — Sentinel across multi-region/workspaces

**Original source:** [Sentinel across multi-region/workspaces](https://techcommunity.microsoft.com/discussions/microsoftsentinel/sentinel-across-multi-regionworkspaces/1205295)
**Voice:** Jeff Walzer
**Date as recorded:** Mar 02, 2020

> We have resource deployed in two regions, East US and Central US. We are using Central US as as zone …

### C295 — Sending logs from one tenant to a different tenant Sentinel instance

**Original source:** [Sending logs from one tenant to a different tenant Sentinel instance](https://techcommunity.microsoft.com/discussions/microsoftsentinel/sending-logs-from-one-tenant-to-a-different-tenant-sentinel-instance/2185531/replies/2195514)
**Voice:** pavankemi
**Date as recorded:** Mar 04, 2021

> Customer has multiple tenants which are owned by Customer

### C380 — Incident Missing Entities

**Original source:** [Incident Missing Entities](https://techcommunity.microsoft.com/discussions/microsoftsentinel/incident-missing-entities/4438300)
**Voice:** FaRa_AVM
**Date as recorded:** Jul 30, 2025

> Yesterday I found out that if I have 2 entities of the same type (In this particular case, two entities …

### C381 — How to stop incidents merging under new incident (MultiStage) in defender.

**Original source:** [How to stop incidents merging under new incident (MultiStage) in defender.](https://techcommunity.microsoft.com/discussions/microsoftthreatprotection/how-to-stop-incidents-merging-under-new-incident-multistage-in-defender-/4472889/replies/4473248)
**Voice:** smavrakis
**Date as recorded:** Nov 25, 2025

> multiple custom rule alerts and analytic rule incidents are being automatically

### C382 — Bulk Closure of old Incidents via PowerShell

**Original source:** [Bulk Closure of old Incidents via PowerShell](https://techcommunity.microsoft.com/discussions/microsoftsentinel/bulk-closure-of-old-incidents-via-powershell/3692413/)
**Voice:** pecific147
**Date as recorded:** Dec 08, 2022

> This works fine for incidents, triggered in last 48 hr. For older incident (older than 48 hr) it is giving …

### C383 — Tips on how to process firewall URL/DNS alerts

**Original source:** [Tips on how to process firewall URL/DNS alerts](https://techcommunity.microsoft.com/discussions/microsoftsentinel/tips-on-how-to-process-firewall-urldns-alerts/4396605)
**Voice:** TheHoff70
**Date as recorded:** Mar 24, 2025

> I don't want to tune them out completely because they might be an indication of something bigger but as the …

### C384 — Fetching alerts from Sentinel using logic apps

**Original source:** [Fetching alerts from Sentinel using logic apps](https://techcommunity.microsoft.com/discussions/microsoftsentinel/fetching-alerts-from-sentinel-using-logic-apps/4384609/replies/4390377)
**Voice:** Zorghost
**Date as recorded:** Feb 22, 2025

> I have a requirement to archive alerts from sentinel. To do that I need to do the following:

### E31 — Recovery is prolonged even with a surviving backup

**Original source:** [Recovery is prolonged even with a surviving backup](https://www.reddit.com/r/sysadmin/comments/1mlgaet/pour_one_out_for_us/)
**Voice:** roger_27
**Date as recorded:** 2025-08-09

> Spent the day restoring from backups from last night.

### E32 — First responders lack clarity while waiting for specialists

**Original source:** [First responders lack clarity while waiting for specialists](https://www.reddit.com/r/sysadmin/comments/1ldzpvb/first_ransomware_attack/)
**Voice:** IntrepidCress5097
**Date as recorded:** 2025-06-17

> I’m a little lost.

### E33 — Operational recovery does not end responder strain

**Original source:** [Operational recovery does not end responder strain](https://www.reddit.com/r/sysadmin/comments/1gv5ja0/ransomware_ptsd/)
**Voice:** Sultans-Of-IT
**Date as recorded:** 2024-11-19

> every time something "weird" happens, I immediately get an adrenaline spike

### C063 — Recommendations for alerting and SIEM

**Original source:** [Recommendations for alerting and SIEM](https://www.reddit.com/r/sysadmin/comments/sbn92z)
**Voice:** bender-bender-bender
**Date as recorded:** January 24 2022 (search-index date)

> This seems impressive but the cost is prohibitive since my company has not really taken security or systems health seriously. …

### C064 — Useful SIEM Info For SysAdmin

**Original source:** [Useful SIEM Info For SysAdmin](https://www.reddit.com/r/sysadmin/comments/gdb8hf)
**Voice:** sa42v
**Date as recorded:** May 04 2020 (search-index date)

> As a Windows SysAdmin, what SIEM information/events should I be asking to be notified from my InfoSec team?

### C065 — Anyone else feel like their SIEM is just expensive log storage?

**Original source:** [Anyone else feel like their SIEM is just expensive log storage?](https://www.reddit.com/r/sysadmin/comments/1mqy2um)
**Voice:** Dudeman972
**Date as recorded:** August 15 2025 (search-index date)

> The only alerts worth acting on come from other tools that we’ve manually integrated, and our “correlation” rules are more …

### C135 — How can I recover from a ransomware attack?

**Original source:** [How can I recover from a ransomware attack?](https://www.reddit.com/r/sysadmin/comments/1wclnh5/how_can_i_recover_from_a_ransomware_attack/)
**Voice:** RJ2_D2_
**Date as recorded:** September 10 2026 (search-index date)

> So, the unthinkable happened to my workplace - we have become the victims of a ransomware attack. We came into …

### C136 — Ransomware.  Steps after recovery

**Original source:** [Ransomware.  Steps after recovery](https://www.reddit.com/r/sysadmin/comments/1vfhfpr/ransomware_steps_after_recovery/)
**Voice:** dherhsc
**Date as recorded:** August 04 2026 (search-index date)

> We have backups...well atleast our vendor says we do. We've done some testing, but not a full test. We have …

### C137 — Ransomware Recovery - What were your lessons learned?

**Original source:** [Ransomware Recovery - What were your lessons learned?](https://www.reddit.com/r/sysadmin/comments/cowwdu)
**Voice:** kckings4906
**Date as recorded:** August 11 2019 (search-index date)

> I have already learned... - We should have have set all file shares used by the general masses to read …

### C138 — Ransomware attack recovery

**Original source:** [Ransomware attack recovery](https://www.reddit.com/r/sysadmin/comments/1m0jlkm/ransomware_attack_recovery/)
**Voice:** Ta_dah
**Date as recorded:** July 15 2025 (search-index date)

> Hi everyone, hope everyones day is going well. I find this subreddit the closest to help on my little IT …

### C141 — Ransomware Attack Recovery Plan and Strategy

**Original source:** [Ransomware Attack Recovery Plan and Strategy](https://www.reddit.com/r/sysadmin/comments/17rinqq)
**Voice:** Krazie8s
**Date as recorded:** Page displayed 3y ago; exact date unverified

> Hi all. We are a smaller org with around 400 users and we are working on building our Ransomware attack …

### C142 — Ransomware Recovery Plan

**Original source:** [Ransomware Recovery Plan](https://www.reddit.com/r/sysadmin/comments/18i7x8e)
**Voice:** Remarkable_Tomato971
**Date as recorded:** Page displayed 3y ago; exact date unverified

> Currently I am the only technical systems manager. We have a business manager and a business development manager as well …

### C143 — That time I saved the company's data and got $625 for it.

**Original source:** [That time I saved the company's data and got $625 for it.](https://www.reddit.com/r/sysadmin/comments/174ph1p)
**Voice:** RaucousRat
**Date as recorded:** Page displayed 3y ago; exact date unverified

> I [posted a few years back](https://www.reddit.com/r/sysadmin/comments/d1ss5w/admin_refuses_to_upgrade_windows_7_and_server/ ) and got a ton of great advice that helped me improve my professional …

### C144 — Ransomware attack is best thing that happend to our company

**Original source:** [Ransomware attack is best thing that happend to our company](https://www.reddit.com/r/sysadmin/comments/16s5bzi)
**Voice:** [deleted]
**Date as recorded:** Page displayed 3y ago; exact date unverified

> We are a financial company that got hit by a ransomware attack twice in a year. With a gap of …

### C145 — Ransomware recovery process

**Original source:** [Ransomware recovery process](https://www.reddit.com/r/sysadmin/comments/11963v2)
**Voice:** KnowWhatIDid
**Date as recorded:** Page displayed 4y ago; exact date unverified

> I'm not on the security team, and I've never been the victim of one, much less one on a wide …

### C146 — Ransomware playbook

**Original source:** [Ransomware playbook](https://www.reddit.com/r/sysadmin/comments/1hrhqww)
**Voice:** CapableWay4518
**Date as recorded:** Page displayed 2y ago; exact date unverified

> We obviously need to work through containment and sanitation but keep logs. I don’t understand how this works. Logically I …

### C213 — Outlook "Report Message" Addon - is that really it?

**Original source:** [Outlook "Report Message" Addon - is that really it?](https://www.reddit.com/r/sysadmin/comments/hnjsqc)
**Voice:** PsychologicalForm
**Date as recorded:** July 08 2020 (search-index date)

> I'm failing to find any way to tie this into any automated response system or find out what its capable …

### C216 — How does your company respond to phishing emails?

**Original source:** [How does your company respond to phishing emails?](https://www.reddit.com/r/sysadmin/comments/hr1hyz)
**Voice:** commandsupernova
**Date as recorded:** July 14 2020 (search-index date)

> EDIT: Thanks so much for all the helpful responses. I'm going to look into Proofpoint, Microsoft ATP, and Exchange Online …

### C218 — How do you all handle phish alert emails?

**Original source:** [How do you all handle phish alert emails?](https://www.reddit.com/r/sysadmin/comments/14zt8s0)
**Voice:** This_guy_works
**Date as recorded:** July 14 2023 (search-index date)

> they go into a shared IT mailbox for us to reivew. That is great and works as expected. The problem …

### C296 — How do you keep your incident response process from turning into chaos?

**Original source:** [How do you keep your incident response process from turning into chaos?](https://www.reddit.com/r/sysadmin/comments/1nk5t1t/how_do_you_keep_your_incident_response_process/)
**Voice:** albaaaaashir
**Date as recorded:** September 18 2025 (search-index date)

> Our IR plan looks great on paper, but in reality, it's a scramble of Slack, calls, and missed updates. Keeping …

### C297 — Skeleton closet unearthed after a security incident

**Original source:** [Skeleton closet unearthed after a security incident](https://www.reddit.com/r/sysadmin/comments/d133sa/skeleton_closet_unearthed_after_a_security/)
**Voice:** lemmycaution0
**Date as recorded:** September 07 2019 (search-index date)

> I am the survivor of this incident a few months ago.

### E41 — Containment request does not complete

**Original source:** [Containment request does not complete](https://www.reddit.com/r/crowdstrike/comments/16oy3oc/network_contain_citrix_issues/)
**Voice:** deathstormer
**Date as recorded:** 2023-09-22

> Console accepts the action, however they just sit in "Pending network containment".

### E42 — Containment status lacks a convenient explanation link

**Original source:** [Containment status lacks a convenient explanation link](https://www.reddit.com/r/crowdstrike/comments/1095ym0/contained_machines_report/)
**Voice:** Anythingelse999999
**Date as recorded:** 2023-01-11

> I am really after the contained hosts, and the reasoning/incident behind it

### C069 — Volume Shadow Snapshot False Positives

**Original source:** [Volume Shadow Snapshot False Positives](https://www.reddit.com/r/crowdstrike/comments/1s1no4g/volume_shadow_snapshot_false_positives/)
**Voice:** ootykue
**Date as recorded:** March 23 2026 (search-index date)

> I've created exclusions for some but others appear to have unique GUID type information in the cmd line. The frequency …

### C070 — Identity Protection Azure IDAAS Integration

**Original source:** [Identity Protection Azure IDAAS Integration](https://www.reddit.com/r/crowdstrike/comments/166rv2k)
**Voice:** NeatoImStuck
**Date as recorded:** December 11 2023 (search-index date)

> We recently setup the Azure IDAAS connector with Identity Protection. Would anyone be willing to share some ideas for this …

### C071 — Fusion Workflow Whitelist IP

**Original source:** [Fusion Workflow Whitelist IP](https://www.reddit.com/r/crowdstrike/comments/19eldvu)
**Voice:** Unlikely-Analyst-411
**Date as recorded:** January 24 2024 (search-index date)

> Dipping my toes into workflows and we're getting some false positives due to an IP subnet being legit despite fitting …

### C072 — Fusion Workflow and Exclusion Question

**Original source:** [Fusion Workflow and Exclusion Question](https://www.reddit.com/r/crowdstrike/comments/1n2kbrr)
**Voice:** RobotCarWash2000
**Date as recorded:** August 28 2025 (search-index date)

> I have staged a Fusion Workflow that contains hosts when OS Credential Dumping is detected. I also have an existing …

### C074 — IOA vs IOC for software allowlisting: how do you handle hash drift when new versions ship?

**Original source:** [IOA vs IOC for software allowlisting: how do you handle hash drift when new versions ship?](https://www.reddit.com/r/crowdstrike/comments/1td4o5x/ioa_vs_ioc_for_software_allowlisting_how_do_you/)
**Voice:** Brief_Trifle_6168
**Date as recorded:** May 14 2026 (search-index date)

> But the obvious problem is scale: every time the vendor ships a new version, the hash changes and we'd have …

### C075 — Fusion Workflows

**Original source:** [Fusion Workflows](https://www.reddit.com/r/crowdstrike/comments/11iqqyw)
**Voice:** lowly_sec_vuln
**Date as recorded:** August 06 2023 (search-index date)

> We also have a workflow that notifies our response team each time a device is contained so they can quickly respond.

### C076 — Crowdstrike UI seems messy/what to check daily?

**Original source:** [Crowdstrike UI seems messy/what to check daily?](https://www.reddit.com/r/crowdstrike/comments/1mqy2nj)
**Voice:** pullpinz81
**Date as recorded:** August 15 2025 (search-index date)

> I’m trying to get a handle on what I should be checking daily to stay on top of things and …

### C077 — CSFalconService.exe attempted to modify a registry key

**Original source:** [CSFalconService.exe attempted to modify a registry key](https://www.reddit.com/r/crowdstrike/comments/1cmjtwf)
**Voice:** Ok-Purpose1717
**Date as recorded:** May 07 2024 (search-index date)

> We keep getting a detection from different devices, where a process is attempting to modify a registry key or value …

### C078 — Types of Critical Alerts You have seen so far?

**Original source:** [Types of Critical Alerts You have seen so far?](https://www.reddit.com/r/crowdstrike/comments/17ef346)
**Voice:** knightsnight_trade
**Date as recorded:** October 23 2023 (search-index date)

> I'm trying to construct a fussion workflow that involve network contains, send messages to endpoint etc on critical detections we …

### C306 — Hindsight Fusion SOAR Workflow

**Original source:** [Hindsight Fusion SOAR Workflow](https://www.reddit.com/r/crowdstrike/comments/1ligr93)
**Voice:** alexandruhera
**Date as recorded:** June 23 2025 (search-index date)

> This repository provides a modular, fully automated forensic analysis pipeline designed for use with **CrowdStrike Falcon Real Time Response (RTR)**. …

### C307 — VSS Audit is not a feature ready for production

**Original source:** [VSS Audit is not a feature ready for production](https://www.reddit.com/r/crowdstrike/comments/qld95r)
**Voice:** hardl3ft
**Date as recorded:** November 05 2021 (search-index date)

> A critical alert means the IR process goes into motion and the SOC is calling us even if it's in …

### C386 — New Host Investigation Dashboard

**Original source:** [New Host Investigation Dashboard](https://www.reddit.com/r/crowdstrike/comments/1bai31z)
**Voice:** r3ptarr
**Date as recorded:** March 09 2024 (search-index date)

> I've had multiple instances where an ip address search identifies a device, but then I go over to host search …

### C387 — Defender ATP vs. Crowdstrike EDR + Threat Graph

**Original source:** [Defender ATP vs. Crowdstrike EDR + Threat Graph](https://www.reddit.com/r/crowdstrike/comments/ig13y5)
**Voice:** BurritoSecurityGuy
**Date as recorded:** August 25 2020 (search-index date)

> We are currently running Defender ATP since we're on E5 - it provides decent protection and allows our dedicated security …

### C388 — How do I find Solarwinds SUNBURST in Falcon

**Original source:** [How do I find Solarwinds SUNBURST in Falcon](https://www.reddit.com/r/crowdstrike/comments/kd4acs)
**Voice:** CarterLawler
**Date as recorded:** December 14 2020 (search-index date)

> Does anyone have steps to follow to see if any of my hosts were compromised by the Solarwinds SUNBURST attack? …

### C390 — Malicious scheduled task - Persistant implant

**Original source:** [Malicious scheduled task - Persistant implant](https://www.reddit.com/r/crowdstrike/comments/1krwd34)
**Voice:** It_joyboy
**Date as recorded:** May 21 2025 (search-index date)

> Upon investigating the detection i found out that there was encoded powershell script trying to make connections to C2 domains. …

### C391 — NGSIEM Licensing Qs

**Original source:** [NGSIEM Licensing Qs](https://www.reddit.com/r/crowdstrike/comments/1dt4u78)
**Voice:** 5thNov
**Date as recorded:** July 01 2024 (search-index date)

> Hi All, I have some questions about the licensing for NGSIEM. If I would have Flacon EDR Complete, Cloud Complete …

### C394 — Best Practices for Naming Conventions when setting up NGSIEM at the data onboarding stage

**Original source:** [Best Practices for Naming Conventions when setting up NGSIEM at the data onboarding stage](https://www.reddit.com/r/crowdstrike/comments/1skpsk7/best_practices_for_naming_conventions_when/)
**Voice:** Dangerous-Ask-2926
**Date as recorded:** April 13 2026 (search-index date)

> We're transitioning from something big and green, where naming conventions can stick with you indefinitely if generated in a less-than-ideal …

### E46 — Context enrichment is a demonstrated conventional baseline

**Original source:** [Context enrichment is a demonstrated conventional baseline](https://www.coinbase.com/blog/scaling-detection-and-response-operations-at-coinbase-pt2)
**Voice:** James Dorgan, Coinbase
**Date as recorded:** 2023-09-15

> a lot of manual digging into logs and systems

### C081 — Scaling Detection and Response Operations at Coinbase pt3

**Original source:** [Scaling Detection and Response Operations at Coinbase pt3](https://www.coinbase.com/blog/scaling-detection-and-response-operations-at-coinbase-pt3/)
**Voice:** By James Dorgan Sep 22, 2023 • 4min read
**Date as recorded:** Sep 22, 2023

> our analysts regularly lacked the context around why the underlying activity for the alert had taken place.

### C317 — Deep Chain Reorganization Detected on Ethereum Classic (ETC)

**Original source:** [Deep Chain Reorganization Detected on Ethereum Classic (ETC)](https://www.coinbase.com/blog/deep-chain-reorganization-detected-on-ethereum-classic-etc)
**Voice:** Coinbase team
**Date as recorded:** Jan 7, 2019

> In order to protect customer funds, we immediately paused interactions with the ETC blockchain.

### C320 — Technical Retro: Remediating the Vulnerability in MakerDAO’s Voting Contracts

**Original source:** [Technical Retro: Remediating the Vulnerability in MakerDAO’s Voting Contracts](https://www.coinbase.com/blog/technical-retro-remediating-the-vulnerability-in-makerdaos-voting-contracts)
**Voice:** Coinbase team
**Date as recorded:** May 9, 2019

> we worked closely with our partners and the MKR team to remediate the vulnerability

### C396 — Scaling Detection and Response Operations at Coinbase Pt.1

**Original source:** [Scaling Detection and Response Operations at Coinbase Pt.1](https://www.coinbase.com/blog/scaling-detection-and-response-operations-at-coinbase)
**Voice:** James Dorgan
**Date as recorded:** Sep 8, 2023

> there’s often a considerable difference between how individual analysts investigate the same alert.

## Focused Purple AI and SentinelOne feedback: 12 additional records

These F01–F12 records are outside the 226-record core denominator. Each quoted phrase is copied from the original research ledger. Some records describe broader SentinelOne products or services rather than Purple AI, and some describe positive experiences.

| ID | Product and direct source | Firsthand voice and short verbatim excerpt | Reported experience and qualification | Journey mapping |
|---|---|---|---|---|
| **F01** | **Purple AI** — [r/SentinelOneXDR, “Purple AI”](https://www.reddit.com/r/SentinelOneXDR/comments/1l9ley9/purple_ai/), June 2025 | `Kekatronicles`: “We resorted to manual query searches.” `TheGrindBastard`: “Hallucinates too much.” `renderbender1`: “The alert summarization is kind of weak” | Several people in one thread reported unsatisfactory query results or summaries and manual fallback. These are distinct voices but **one thread record**; test conditions and prompt quality are unknown. | **4 Gather the facts; 5 Decide what is happening; 10 Record and explain; 12 Look for attacks without a warning.** The strongest direct link is to fact-gathering/search; summary quality matters when explaining a case. |
| **F02** | **Purple AI** — [r/SentinelOneXDR, “Threat Hunting with Purple AI”](https://www.reddit.com/r/SentinelOneXDR/comments/1p1cmxw/threat_hunting_with_purple_ai/), November 2025 | `sammysosa69`: “Purple AI is useful to get started on a search, but I would not rely on it alone for threat hunting.” | User recommends Data Lake searches and dashboards for the rest of the hunt. In the same thread, `Robbbbbbbbb` says Purple helps senior analysts craft queries and juniors learn; the limitation is **standalone sufficiency**, not zero value. | **12 Look for attacks without a warning; 4 Gather the facts.** |
| **F03** | **Purple AI** — [r/cybersecurity, “Has anyone tried SentinelOne's Purple AI?”](https://www.reddit.com/r/cybersecurity/comments/1cbz092/has_anyone_tried_sentinelones_purple_ai_what_are/), August 2024 follow-up | `jmk5151`: “we like it!” and “that's not available in the data now.” | This hands-on user reported much faster answers but said a requested endpoint-data question was unavailable at the time. This is a **positive counterexample with a data-coverage limit**, from an early product version. Another commenter in the thread said “we did not keep it” but later disclosed they had **never used Purple AI**; that sentiment is excluded from firsthand complaint counts. | **1 Make sure monitoring works; 4 Gather the facts; 12 Look for attacks without a warning.** The missing data constrains what AI can answer. |
| **F04** | **SentinelOne Operations Center UI, not Purple AI** — [r/SentinelOneXDR, “The newer SOC console feels sluggish”](https://www.reddit.com/r/SentinelOneXDR/comments/1to4iw2/the_newer_soc_console_feels_sluggish/), 2026 | `Dracozirion`: “bugs (filtering, switching menus,..).” `naes724`: “It is extremely slow.” | OP says their team used the new console for over a year; several replies report slowness. A self-identified SentinelOne product-team member said UI performance was a priority. This is a console performance report, not evidence that Purple AI's model is slow. | **2 Open the incident queue; 3 Choose what needs attention.** Navigation and filtering slow the analyst's path to a case. |
| **F05** | **SentinelOne Data Lake access and enablement, not a Purple AI quality failure** — [r/SentinelOneXDR, training question](https://www.reddit.com/r/SentinelOneXDR/comments/1ionfrx/is_there_any_good_training_for_understanding_the/), February 2025 | `CharcoalGreyWolf`: “I don't really get anything I can actually do when clicking on Purple AI itself” | MSP user reported reseller/SKU access constraints, struggled with query training, and sought a server-connectivity alert. Replies proposed access/training routes and supplied a candidate query. Historical packaging/access claim needs current confirmation. | **1 Make sure monitoring works; 11 Learn and reduce repeat work; 12 Look for attacks without a warning.** This is a purchasing and skill barrier around the workflow, not a model-output complaint. |
| **F06** | **SentinelOne alert setup; Purple AI mentioned** — [r/SentinelOneXDR, break-glass account notification](https://www.reddit.com/r/SentinelOneXDR/comments/1jjtemg/notification_for_breakglass_accounts/), March 2025 | `ThsGuyRightHere`: “it doesn't look like S1's own auth activity goes into the data lake (either that, or it does and I'm just missing it).” | User could not initially find a straightforward way to alert on emergency-admin login. A later reply supplied an ActivityFeed query and STAR-rule approach, so **do not present this as a confirmed data gap or unresolved defect**. It does show discoverability friction. | **1 Make sure monitoring works; 11 Learn and reduce repeat work.** The user was trying to create a reliable warning. |
| **F07** | **SentinelOne-associated SOC service, not Purple AI** — [r/msp, “SIEM/SOC/MDR in 2026”](https://www.reddit.com/r/msp/comments/1vuif8s/siemsocmdr_in_2026/), August 2026 | `Trilobyte75`: “tons of false positives and not at all responsive/communicative with our team.” | User says their prior employer moved from SentinelOne to another managed service. The exact service tier and case mix are not stated; this is a service-experience comparison, not proof of a Purple AI issue. | **3 Choose what needs attention; 7 Get the right people to act.** Noise and poor communication are distinct pains. |
| **F08** | **Purple AI** — [PeerSpot firsthand answer, “What needs improvement with Purple AI?”](https://www.peerspot.com/questions/what-needs-improvement-with-purple-ai), March 18, 2026 | `Kandregula Sathvik`, security engineer: “Purple AI is more passive in SentinelOne. It's not active.” | User wants AI more embedded in the active threat view, with a threat overview, next-step guidance and clearer query-building help. The same author calls the analysis and hunting features useful. This is a request for a different workflow shape, not proof current features are absent today. | **3 Choose what needs attention; 4 Gather the facts; 5 Decide what is happening; 12 Look for attacks without a warning.** |
| **F09** | **Purple AI** — [PeerSpot direct review by `reviewer2811069`](https://www.peerspot.com/products/purple-ai-reviews), March 25, 2026 | IT security analyst: “Sometimes Purple AI provides too generic responses for complex alerts, particularly at levels classified as high or critical.” | Author says low/medium alerts save time but higher-severity cases still need manual review; also reports occasional loading/alert-display issues. Do not turn a high-severity limitation into a claim that all summaries fail. | **4 Gather the facts; 5 Decide what is happening.** A generic answer is least useful where uncertainty and stakes are high. |
| **F10** | **Purple AI** — [PeerSpot direct review by `reviewer2799597`](https://www.peerspot.com/products/purple-ai-reviews), March 19, 2026 | SOC analyst: “There is a significant gap for automation.” | Author praises concise incident summaries but asks for a complete proposed analysis and remediation plan with analyst confirmation or authorization. This is a product request; later feature releases must be checked before calling it an unfilled current gap. | **5 Decide what is happening; 7 Get the right people to act; 8 Stop harm and check the result.** The requested flow goes beyond reading a summary. |
| **F11** | **Purple AI** — [AWS Marketplace-hosted firsthand review supplied by PeerSpot](https://aws.amazon.com/marketplace/reviews/reviews-list/prodview-snyh35hk3226e?filter=ALL&page=3&rating=4&sort=NEWEST), May 20, 2026 | `reviewer2843736`, security analyst: “I do not think the STAR rule query in Purple AI is that efficient and not running as expected.” | Reviewer likes Purple AI for product guidance but reports that generated custom-rule queries did not work as expected in their environment. Their support experience is a separate issue. This review is **republished by AWS from PeerSpot**, so it is one author/source account, not independent AWS corroboration. | **11 Learn and reduce repeat work; 12 Look for attacks without a warning.** The failure is at turning an investigation into a working detection rule. |
| **F12** | **Purple AI and data-lake economics** — [PeerSpot firsthand answer by Mohan Janarthanan](https://www.peerspot.com/questions/what-needs-improvement-with-purple-ai), February 11, 2026 | `Mohan Janarthanan`: “the only concern is the prompting requirement.” | Author also identifies ingestion-based pricing at scale as a concern and says prompt sensitivity is common to AI tools. They otherwise report value in threat hunting. This is a usability/economics issue across the journey, not a specific incident-stage failure. | **12 Look for attacks without a warning; cross-cutting adoption cost.** |

## Supplemental concept-validation accounts: 3 additional records

These S01–S03 records are also outside the 226-record core denominator.

| ID | Direct primary source | Short verbatim excerpt | What the account supports and does not prove | Journey link |
|---|---|---|---|---|
| **S01** | [r/cybersecurity: AppSec without a defined development lifecycle](https://www.reddit.com/r/cybersecurity/comments/1qiind9/how_in_the_hell_can_application_security_work/), author `JColemanG` | “no real change control, and almost zero concept of ownership.” | The author describes discovering applications after deployment and unclear security checkpoints. This supports the need for an owned release review; it does **not** report using an incident-informed AI reviewer. | **11 Learn and reduce repeat work**, with a future-release extension. |
| **S02** | [r/cybersecurity: Security-to-application remediation handoff](https://www.reddit.com/r/cybersecurity/comments/1ecy7lj/so_i_just_got_jumped_in_a_meeting/), author `kielrandor` | “we (Security) are making too much work for them” | The author describes disagreement over priorities and remediation guidance between security and application support. This supports contextual, owner-aware recommendations; it does **not** establish that AI would resolve the organizational conflict. | **7 Get the right people to act; 11 Learn and reduce repeat work.** |
| **S03** | [r/rubrik: recovery-plan API experience](https://www.reddit.com/r/rubrik/comments/1tdxpmt/managing_rubrik_orchestrated_recovery_via_the/), author `Living_Obligation618` | “anything more than ~25 VMs overwhelms the Azure rate limit.” | In a solved follow-up, the user reports a scale limit while automating Azure VM recovery-plan membership. This is a direct account of integration friction, not a general Rubrik performance benchmark or proof that a new recovery agent is needed. | **9 Restore services safely**, adjacent product-integration issue. |

## Named accounts referenced in the PRFAQ

N01 is already core record C396 and is not an additional source. N02 and N03 are outside the 226-record core denominator. These people did not endorse AfterShield.

| ID | Named source and published role | Exact short excerpt used in the press release | Relevance and limit |
|---|---|---|---|
| **N01 / C396** | James Dorgan, principal incident responder in Coinbase's CSIRT at the time, author of [*Scaling Detection and Response Operations at Coinbase Pt. 1*](https://www.coinbase.com/blog/scaling-detection-and-response-operations-at-coinbase); role in [BSides London 2023 speaker bio](https://sched.securitybsides.org.uk/bsides-london-2023/speaker/) | “there’s often a considerable difference between how individual analysts investigate the same alert.” | Supports the need for consistent, reviewable incident evidence. His article describes Coinbase's own investigation platform, not AfterShield. |
| **N02** | Philip Martin, then Coinbase chief security officer, author of [*Responding to Firefox 0-days in the Wild*](https://www.coinbase.com/blog/responding-to-firefox-0-days-in-the-wild); role in the article's author bio | “we were comfortable that we had achieved containment in our environment” | Describes the team's threshold before a next response step. It illustrates why verifying containment matters, not a reported failure of Coinbase's response. |
| **N03** | Michael Recachinas, staff security engineer at GitHub, author of [*How GitHub Gave Every Repository a Durable Owner*](https://github.blog/security/application-security/how-github-gave-every-repository-a-durable-owner/); role in the article's author bio | “we had no clear way to route remediation work.” | Describes ownership friction in GitHub's secret-scanning remediation. It does not establish that an incident-informed agent would resolve it. |

