Rule Parameters
Daily Alert Volume
Detection Coverage Over Time
Alerts/Day
0
Generated alerts
Coverage
0%
Threats detected
Noise Ratio
0%
False positives
Efficiency
0
Coverage/Alert
Tuning Tips: Lower thresholds increase detection but generate more alerts. Wider time windows catch slow attacks but may create noise. Balance coverage against analyst capacity (target: 20-50 alerts/day for a single analyst).