IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  SOC sizing and Offence false positive rate

    Posted Wed November 30, 2022 05:55 AM
    Hi All,

    We're busy tuning our QR7.4 deployment trying to figure out how many analysists need to be monitoring a console of 10,000EPS and what a acceptable false positive rate shoudl be.

    Happy for any advice.


  • 2.  RE: SOC sizing and Offence false positive rate

    Posted Fri December 16, 2022 08:47 AM
    Hi we just discussed this issue last month in here. 42 is the answer. False pos maybe between 50 and 100 %. Two analysts should cover this. If not your tuning needs to get fixed.

    ------------------------------
    [Karl] [Jaeger] [Business Partner]
    [QRadar Specialist]
    [pro4bizz]
    [Karlsruhe] [Germany]
    [4972190981722]
    ------------------------------