<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Siem on Njeru Mtwaiti</title>
    <link>https://blog.njerumtwaiti.com/tags/siem/</link>
    <description>Recent content in Siem on Njeru Mtwaiti</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Sat, 18 Oct 2025 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://blog.njerumtwaiti.com/tags/siem/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SIEM Tuning From the Field: Cutting Noise Without Going Blind</title>
      <link>https://blog.njerumtwaiti.com/posts/siem-tuning-from-the-field/</link>
      <pubDate>Sat, 18 Oct 2025 00:00:00 +0000</pubDate>
      <guid>https://blog.njerumtwaiti.com/posts/siem-tuning-from-the-field/</guid>
      <description>&lt;p&gt;SIEM tuning is the SOC work nobody talks about because it&amp;rsquo;s unglamorous. There&amp;rsquo;s no clean exploit chain to demonstrate, no CVE to drop. It&amp;rsquo;s the slow work of making your detection layer actually useful instead of a source of alert fatigue that trains analysts to ignore everything.&lt;/p&gt;&#xA;&lt;p&gt;These are notes from production — from real log sources, real false positive storms, and real threats that needed catching.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-false-positive-problem&#34;&gt;&#xA;  The False Positive Problem&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#the-false-positive-problem&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;A poorly tuned SIEM is worse than no SIEM. When analysts are triaging 500 alerts a day and 490 of them are junk, two things happen:&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
