Alert Triage
Definition
The process of reviewing SIEM-generated alerts to determine which are genuine security events and which are false positives. In forensic investigations, alert triage also involves determining which suppressed or dismissed alerts may have indicated the incident at an earlier stage.
- Purpose
- Sort SIEM alerts into genuine events and false positives
- Forensic use
- Reviewing suppressed or dismissed alerts after an incident
- Goal
- Identify earliest indicator the incident was missed
Common questions
Why would investigators look back at alerts that were already dismissed as false positives?+
An alert dismissed at the time as noise, without the benefit of hindsight, may in retrospect line up with the confirmed intrusion timeline, so reviewing the suppression history can reveal exactly when the attack first became visible to the monitoring system.
How does alert triage differ from alert correlation?+
Triage is the human or automated decision process that classifies each alert as real or false, while correlation is the earlier step of grouping raw events into a coherent alert in the first place, so triage acts on the output correlation produces.
Related terms
- Chain of Custody
- The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
- Log Correlation
- The process of matching related events from different log sources using shared attributes such as IP address, username, timestamp, or session ID....
- Normalisation
- The process of converting log data from different vendors and formats into a common schema so that fields can be compared across...
- Retention Policy
- An organisation's rule specifying how long log data is stored before deletion or archiving. Policies are typically driven by compliance requirements and...
- SIEM
- Security Information and Event Management. A platform that ingests log streams from multiple sources, normalises them to a common schema, and applies...