{"id":166,"date":"2020-09-24T20:32:31","date_gmt":"2020-09-24T20:32:31","guid":{"rendered":"https:\/\/arter-demo.bslthemes.com\/?page_id=166"},"modified":"2020-09-24T20:32:31","modified_gmt":"2020-09-24T20:32:31","slug":"blog","status":"publish","type":"page","link":"https:\/\/logsmith.io\/index.php\/blog\/","title":{"rendered":"Blog"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"166\" class=\"elementor elementor-166\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-66cb952 elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"66cb952\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-no\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-edca18a\" data-id=\"edca18a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-681945f elementor-widget elementor-widget-arter-blog-grid\" data-id=\"681945f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"arter-blog-grid.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\n\t\t<!-- container -->\n\t\t<div class=\"container-fluid\">\n\n\t\t<!-- row -->\n\t\t<div class=\"row\">\n\t\t  \t\t  <!-- col -->\n\t\t  <div class=\"col-lg-12\">\n\t\t    <!-- section title -->\n\t\t    <div class=\"art-section-title\">\n\t\t      <!-- title frame -->\n\t\t      <div class=\"art-title-frame\">\n\t\t        <!-- title -->\n\t\t        <h4 class=\"art-title-h\">\n\t\t    \t<span >\n\t\t          \tBlog\t\t         <\/span>\n\t\t    \t<\/h4>\n\t\t      <\/div>\n\t\t      <!-- title frame end -->\n\t\t    <\/div>\n\t\t    <!-- section title end -->\n\t\t  <\/div>\n\t\t  <!-- col end -->\n\t\t  \n\t\t  \t\t  \t\t  <!-- col -->\n\t\t  <div class=\"col-lg-6\">\n\t\t    \n\n<!-- blog post card -->\n<div class=\"art-a art-blog-card\">\n  <div id=\"post-369\" class=\"post-369 post type-post status-publish format-standard hentry category-masterclass tag-detection-engineering tag-detection-as-code tag-gitlab tag-masterclass tag-splunk-es\">\n\t  <!-- post cover -->\n\t  \t\t\n\t\t\t  <!-- post cover end -->\n\t  <!-- post description -->\n\t  <div class=\"art-post-description\">\n\t  \t\t\t<div class=\"art-project-category mb-15\">\n\t\t\t<a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/28\/detection-as-code\/\">\n\t\t\t\t<span class=\"art-el-date\">October 28, 2025<\/span>\n\t\t\t<\/a>\n\t\t\t \/ <span class=\"art-el-category\">Masterclass<\/span>\t\t<\/div>\n\t\t\t    <!-- title -->\n\t    <a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/28\/detection-as-code\/\">\n\t      <h5 class=\"mb-15\">\ud83d\udd27 Detection-as-Code: What It Really Means<\/h5>\n\t    <\/a>\n\t    \t    <!-- text -->\n\t    <div class=\"art-el-description\">\n\t    \t<p>Masterclass Series \u2013 Part 2 \ud83e\udded TL;DR: It\u2019s Not Just \u201cPut Your Rules in Git\u201d \u201cDetection-as-Code\u201d sounds like a trendy&#8230; <\/p>\n<div class=\"art-el-more\"><a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/28\/detection-as-code\/\" class=\"art-link art-color-link art-w-chevron\">Read more<\/a><\/div>\n\t    <\/div>\n\t    \t  <\/div>\n\t  <!-- post description end -->\n  <\/div>\n<\/div>\n<!-- blog post card end -->\t\t  <\/div>\n\t\t  <!-- col end -->\n\t\t  \t\t  <!-- col -->\n\t\t  <div class=\"col-lg-6\">\n\t\t    \n\n<!-- blog post card -->\n<div class=\"art-a art-blog-card\">\n  <div id=\"post-367\" class=\"post-367 post type-post status-publish format-standard hentry category-insights tag-alert-fatigue tag-detection-engineering tag-insight tag-splunk-es\">\n\t  <!-- post cover -->\n\t  \t\t\n\t\t\t  <!-- post cover end -->\n\t  <!-- post description -->\n\t  <div class=\"art-post-description\">\n\t  \t\t\t<div class=\"art-project-category mb-15\">\n\t\t\t<a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/23\/the-cost-of-crying-wolf\/\">\n\t\t\t\t<span class=\"art-el-date\">October 23, 2025<\/span>\n\t\t\t<\/a>\n\t\t\t \/ <span class=\"art-el-category\">Insights<\/span>\t\t<\/div>\n\t\t\t    <!-- title -->\n\t    <a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/23\/the-cost-of-crying-wolf\/\">\n\t      <h5 class=\"mb-15\">The Cost of Crying Wolf: Why False Positives Are Killing Your SOC<\/h5>\n\t    <\/a>\n\t    \t    <!-- text -->\n\t    <div class=\"art-el-description\">\n\t    \t<p>Introduction It\u2019s not the alerts you miss that break a SOC \u2014 it\u2019s the thousands you never should have seen&#8230; <\/p>\n<div class=\"art-el-more\"><a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/23\/the-cost-of-crying-wolf\/\" class=\"art-link art-color-link art-w-chevron\">Read more<\/a><\/div>\n\t    <\/div>\n\t    \t  <\/div>\n\t  <!-- post description end -->\n  <\/div>\n<\/div>\n<!-- blog post card end -->\t\t  <\/div>\n\t\t  <!-- col end -->\n\t\t  \t\t  <!-- col -->\n\t\t  <div class=\"col-lg-6\">\n\t\t    \n\n<!-- blog post card -->\n<div class=\"art-a art-blog-card\">\n  <div id=\"post-363\" class=\"post-363 post type-post status-publish format-standard hentry category-case-study tag-case-study tag-detection-engineering tag-log-normalisation\">\n\t  <!-- post cover -->\n\t  \t\t\n\t\t\t  <!-- post cover end -->\n\t  <!-- post description -->\n\t  <div class=\"art-post-description\">\n\t  \t\t\t<div class=\"art-project-category mb-15\">\n\t\t\t<a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/16\/when-cim-mapping-goes-sideways\/\">\n\t\t\t\t<span class=\"art-el-date\">October 16, 2025<\/span>\n\t\t\t<\/a>\n\t\t\t \/ <span class=\"art-el-category\">Case Study<\/span>\t\t<\/div>\n\t\t\t    <!-- title -->\n\t    <a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/16\/when-cim-mapping-goes-sideways\/\">\n\t      <h5 class=\"mb-15\">When CIM Mapping Goes Sideways: Lessons from a Broken Detection<\/h5>\n\t    <\/a>\n\t    \t    <!-- text -->\n\t    <div class=\"art-el-description\">\n\t    \t<p>\ud83d\udd0e Introduction Everything looked good on paper:\u2705 The detection rule was written.\u2705 The sourcetype was CIM-mapped.\u2705 The data model was&#8230; <\/p>\n<div class=\"art-el-more\"><a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/16\/when-cim-mapping-goes-sideways\/\" class=\"art-link art-color-link art-w-chevron\">Read more<\/a><\/div>\n\t    <\/div>\n\t    \t  <\/div>\n\t  <!-- post description end -->\n  <\/div>\n<\/div>\n<!-- blog post card end -->\t\t  <\/div>\n\t\t  <!-- col end -->\n\t\t  \t\t  <!-- col -->\n\t\t  <div class=\"col-lg-6\">\n\t\t    \n\n<!-- blog post card -->\n<div class=\"art-a art-blog-card\">\n  <div id=\"post-356\" class=\"post-356 post type-post status-publish format-standard hentry category-masterclass tag-detection-engineering tag-masterclass tag-playbook tag-splunk\">\n\t  <!-- post cover -->\n\t  \t\t\n\t\t\t  <!-- post cover end -->\n\t  <!-- post description -->\n\t  <div class=\"art-post-description\">\n\t  \t\t\t<div class=\"art-project-category mb-15\">\n\t\t\t<a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/14\/macro-driven-rule-logic\/\">\n\t\t\t\t<span class=\"art-el-date\">October 14, 2025<\/span>\n\t\t\t<\/a>\n\t\t\t \/ <span class=\"art-el-category\">Masterclass<\/span>\t\t<\/div>\n\t\t\t    <!-- title -->\n\t    <a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/14\/macro-driven-rule-logic\/\">\n\t      <h5 class=\"mb-15\">\ud83e\udde0 Macro-Driven Rule Logic &#8211; Splunk Masterclass 1\/5<\/h5>\n\t    <\/a>\n\t    \t    <!-- text -->\n\t    <div class=\"art-el-description\">\n\t    \t<p>\ud83d\udc4b Welcome to the LogSmith Splunk Masterclass This series is for detection engineers, Splunk admins, and SOC architects who want&#8230; <\/p>\n<div class=\"art-el-more\"><a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/14\/macro-driven-rule-logic\/\" class=\"art-link art-color-link art-w-chevron\">Read more<\/a><\/div>\n\t    <\/div>\n\t    \t  <\/div>\n\t  <!-- post description end -->\n  <\/div>\n<\/div>\n<!-- blog post card end -->\t\t  <\/div>\n\t\t  <!-- col end -->\n\t\t  \t\t  <!-- col -->\n\t\t  <div class=\"col-lg-6\">\n\t\t    \n\n<!-- blog post card -->\n<div class=\"art-a art-blog-card\">\n  <div id=\"post-351\" class=\"post-351 post type-post status-publish format-standard hentry category-insights tag-free-resource tag-insight\">\n\t  <!-- post cover -->\n\t  \t\t\n\t\t\t  <!-- post cover end -->\n\t  <!-- post description -->\n\t  <div class=\"art-post-description\">\n\t  \t\t\t<div class=\"art-project-category mb-15\">\n\t\t\t<a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/07\/5-signs-your-siem-is-too-noisy\/\">\n\t\t\t\t<span class=\"art-el-date\">October 7, 2025<\/span>\n\t\t\t<\/a>\n\t\t\t \/ <span class=\"art-el-category\">Insights<\/span>\t\t<\/div>\n\t\t\t    <!-- title -->\n\t    <a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/07\/5-signs-your-siem-is-too-noisy\/\">\n\t      <h5 class=\"mb-15\">5 Signs Your SIEM Is Too Noisy<\/h5>\n\t    <\/a>\n\t    \t    <!-- text -->\n\t    <div class=\"art-el-description\">\n\t    \t<p>And what to do about it before your SOC burns out Your SIEM might look functional. It might be alerting&#8230;. <\/p>\n<div class=\"art-el-more\"><a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/07\/5-signs-your-siem-is-too-noisy\/\" class=\"art-link art-color-link art-w-chevron\">Read more<\/a><\/div>\n\t    <\/div>\n\t    \t  <\/div>\n\t  <!-- post description end -->\n  <\/div>\n<\/div>\n<!-- blog post card end -->\t\t  <\/div>\n\t\t  <!-- col end -->\n\t\t  \t\t  <!-- col -->\n\t\t  <div class=\"col-lg-6\">\n\t\t    \n\n<!-- blog post card -->\n<div class=\"art-a art-blog-card\">\n  <div id=\"post-344\" class=\"post-344 post type-post status-publish format-standard has-post-thumbnail hentry category-case-study tag-alert-fatigue tag-case-study tag-detection-engineering tag-log-normalisation tag-splunk-es\">\n\t  <!-- post cover -->\n\t  \t\t\t\t<a class=\"art-port-cover post-thumbnail\" href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/\">\n\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/logsmith.io\/wp-content\/uploads\/2025\/10\/data_pipe-1024x768.png\" class=\"attachment-arter_1280x768 size-arter_1280x768 wp-post-image\" alt=\"Case Study : Taming the 21,000-Alert-a-Day SIEM\" \/>\t\t<\/a>\n\t\t\n\t\t\t  <!-- post cover end -->\n\t  <!-- post description -->\n\t  <div class=\"art-post-description\">\n\t  \t\t\t<div class=\"art-project-category mb-15\">\n\t\t\t<a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/\">\n\t\t\t\t<span class=\"art-el-date\">October 6, 2025<\/span>\n\t\t\t<\/a>\n\t\t\t \/ <span class=\"art-el-category\">Case Study<\/span>\t\t<\/div>\n\t\t\t    <!-- title -->\n\t    <a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/\">\n\t      <h5 class=\"mb-15\">Case Study : Taming the 21,000-Alert-a-Day SIEM<\/h5>\n\t    <\/a>\n\t    \t    <!-- text -->\n\t    <div class=\"art-el-description\">\n\t    \t<p>How I helped restore clarity and control to a chaotic Splunk ES environment<\/p>\n\t    <\/div>\n\t    \t  <\/div>\n\t  <!-- post description end -->\n  <\/div>\n<\/div>\n<!-- blog post card end -->\t\t  <\/div>\n\t\t  <!-- col end -->\n\t\t  \t\t  \t\t<\/div>\n\t\t<!-- row end -->\n\n\t\t<\/div>\n\t\t<!-- container end -->\n\n\t\t\t\t<!-- container -->\n\t\t<div class=\"container-fluid\">\n\n\t\t<!-- row -->\n\t\t<div class=\"row\">\n\n\t\t  <!-- col -->\n\t\t  <div class=\"col-lg-12\">\n\n\t\t  \t\t\t    <!-- pagination -->\n\t\t    <div class=\"art-a art-pagination\">\n\t\t      \t<span aria-current=\"page\" class=\"page-numbers current\">1<\/span>\n<a class=\"page-numbers\" href=\"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/pages\/166\/page\/2\/\">2<\/a>\n<a class=\"next page-numbers\" href=\"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/pages\/166\/page\/2\/\">Next<\/a>\t\t    <\/div>\n\t\t    <!-- pagination end -->\n\t\t    \n\t\t    \t\t  <\/div>\n\t\t  <!-- col end -->\n\n\t\t<\/div>\n\t\t<!-- row end -->\n\n\t\t<\/div>\n\t\t<!-- container end -->\n\t\t\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Blog September 24, 2020 \/ Design, Events, Technology Follow your own design process. My job is simple and sophisticated, so&#8230; <\/p>\n<div class=\"art-el-more\"><a href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/\" class=\"art-link art-color-link art-w-chevron\">Read more<\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"template-layout-builder.php","meta":{"_acf_changed":false,"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"iawp_total_views":1,"footnotes":""},"class_list":["post-166","page","type-page","status-publish","hentry"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"How I helped restore clarity and control to a chaotic Splunk ES environment\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"LogSmith -\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Case Study : Taming the 21,000-Alert-a-Day SIEM - LogSmith\" \/>\n\t\t<meta property=\"og:description\" content=\"How I helped restore clarity and control to a chaotic Splunk ES environment\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-10-06T13:14:36+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-10-06T13:14:38+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Case Study : Taming the 21,000-Alert-a-Day SIEM - LogSmith\" \/>\n\t\t<meta name=\"twitter:description\" content=\"How I helped restore clarity and control to a chaotic Splunk ES environment\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/2025\\\/10\\\/06\\\/taming-the-21000-alert-siem\\\/#blogposting\",\"name\":\"Case Study : Taming the 21,000-Alert-a-Day SIEM - LogSmith\",\"headline\":\"Case Study : Taming the 21,000-Alert-a-Day SIEM\",\"author\":{\"@id\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/author\\\/stebutty\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/logsmith.io\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/logsmith.io\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/data_pipe.png\",\"width\":1024,\"height\":1024},\"datePublished\":\"2025-10-06T13:14:36+00:00\",\"dateModified\":\"2025-10-06T13:14:38+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/2025\\\/10\\\/06\\\/taming-the-21000-alert-siem\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/2025\\\/10\\\/06\\\/taming-the-21000-alert-siem\\\/#webpage\"},\"articleSection\":\"Case Study, Alert Fatigue, Case Study, Detection Engineering, Log Normalisation, Splunk ES\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/2025\\\/10\\\/06\\\/taming-the-21000-alert-siem\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/logsmith.io#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/logsmith.io\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/blog\\\/#listItem\",\"name\":\"Blog\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/blog\\\/#listItem\",\"position\":2,\"name\":\"Blog\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/logsmith.io#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/logsmith.io\\\/#organization\",\"name\":\"LogSmith\",\"url\":\"https:\\\/\\\/logsmith.io\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/author\\\/stebutty\\\/#author\",\"url\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/author\\\/stebutty\\\/\",\"name\":\"stebutty\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/2025\\\/10\\\/06\\\/taming-the-21000-alert-siem\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e1dba347d57277353b989e49264b8b013fe6eed788c3370ebda5270222c5eefb?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"stebutty\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/2025\\\/10\\\/06\\\/taming-the-21000-alert-siem\\\/#webpage\",\"url\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/2025\\\/10\\\/06\\\/taming-the-21000-alert-siem\\\/\",\"name\":\"Case Study : Taming the 21,000-Alert-a-Day SIEM - LogSmith\",\"description\":\"How I helped restore clarity and control to a chaotic Splunk ES environment\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/logsmith.io\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/2025\\\/10\\\/06\\\/taming-the-21000-alert-siem\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/author\\\/stebutty\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/author\\\/stebutty\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/logsmith.io\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/data_pipe.png\",\"@id\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/2025\\\/10\\\/06\\\/taming-the-21000-alert-siem\\\/#mainImage\",\"width\":1024,\"height\":1024},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/logsmith.io\\\/index.php\\\/2025\\\/10\\\/06\\\/taming-the-21000-alert-siem\\\/#mainImage\"},\"datePublished\":\"2025-10-06T13:14:36+00:00\",\"dateModified\":\"2025-10-06T13:14:38+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/logsmith.io\\\/#website\",\"url\":\"https:\\\/\\\/logsmith.io\\\/\",\"name\":\"LogSmith\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/logsmith.io\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Case Study : Taming the 21,000-Alert-a-Day SIEM - LogSmith","description":"How I helped restore clarity and control to a chaotic Splunk ES environment","canonical_url":"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/#blogposting","name":"Case Study : Taming the 21,000-Alert-a-Day SIEM - LogSmith","headline":"Case Study : Taming the 21,000-Alert-a-Day SIEM","author":{"@id":"https:\/\/logsmith.io\/index.php\/author\/stebutty\/#author"},"publisher":{"@id":"https:\/\/logsmith.io\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/logsmith.io\/wp-content\/uploads\/2025\/10\/data_pipe.png","width":1024,"height":1024},"datePublished":"2025-10-06T13:14:36+00:00","dateModified":"2025-10-06T13:14:38+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/#webpage"},"isPartOf":{"@id":"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/#webpage"},"articleSection":"Case Study, Alert Fatigue, Case Study, Detection Engineering, Log Normalisation, Splunk ES"},{"@type":"BreadcrumbList","@id":"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/logsmith.io#listItem","position":1,"name":"Home","item":"https:\/\/logsmith.io","nextItem":{"@type":"ListItem","@id":"https:\/\/logsmith.io\/index.php\/blog\/#listItem","name":"Blog"}},{"@type":"ListItem","@id":"https:\/\/logsmith.io\/index.php\/blog\/#listItem","position":2,"name":"Blog","previousItem":{"@type":"ListItem","@id":"https:\/\/logsmith.io#listItem","name":"Home"}}]},{"@type":"Organization","@id":"https:\/\/logsmith.io\/#organization","name":"LogSmith","url":"https:\/\/logsmith.io\/"},{"@type":"Person","@id":"https:\/\/logsmith.io\/index.php\/author\/stebutty\/#author","url":"https:\/\/logsmith.io\/index.php\/author\/stebutty\/","name":"stebutty","image":{"@type":"ImageObject","@id":"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/e1dba347d57277353b989e49264b8b013fe6eed788c3370ebda5270222c5eefb?s=96&d=mm&r=g","width":96,"height":96,"caption":"stebutty"}},{"@type":"WebPage","@id":"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/#webpage","url":"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/","name":"Case Study : Taming the 21,000-Alert-a-Day SIEM - LogSmith","description":"How I helped restore clarity and control to a chaotic Splunk ES environment","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/logsmith.io\/#website"},"breadcrumb":{"@id":"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/#breadcrumblist"},"author":{"@id":"https:\/\/logsmith.io\/index.php\/author\/stebutty\/#author"},"creator":{"@id":"https:\/\/logsmith.io\/index.php\/author\/stebutty\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/logsmith.io\/wp-content\/uploads\/2025\/10\/data_pipe.png","@id":"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/#mainImage","width":1024,"height":1024},"primaryImageOfPage":{"@id":"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/#mainImage"},"datePublished":"2025-10-06T13:14:36+00:00","dateModified":"2025-10-06T13:14:38+00:00"},{"@type":"WebSite","@id":"https:\/\/logsmith.io\/#website","url":"https:\/\/logsmith.io\/","name":"LogSmith","inLanguage":"en-US","publisher":{"@id":"https:\/\/logsmith.io\/#organization"}}]},"og:locale":"en_US","og:site_name":"LogSmith -","og:type":"article","og:title":"Case Study : Taming the 21,000-Alert-a-Day SIEM - LogSmith","og:description":"How I helped restore clarity and control to a chaotic Splunk ES environment","og:url":"https:\/\/logsmith.io\/index.php\/2025\/10\/06\/taming-the-21000-alert-siem\/","article:published_time":"2025-10-06T13:14:36+00:00","article:modified_time":"2025-10-06T13:14:38+00:00","twitter:card":"summary_large_image","twitter:title":"Case Study : Taming the 21,000-Alert-a-Day SIEM - LogSmith","twitter:description":"How I helped restore clarity and control to a chaotic Splunk ES environment"},"aioseo_meta_data":{"post_id":"166","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2025-09-26 10:27:22","updated":"2025-09-26 10:27:22","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/logsmith.io\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tBlog\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/logsmith.io"},{"label":"Blog","link":"https:\/\/logsmith.io\/index.php\/blog\/"}],"_links":{"self":[{"href":"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/pages\/166","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/comments?post=166"}],"version-history":[{"count":0,"href":"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/pages\/166\/revisions"}],"wp:attachment":[{"href":"https:\/\/logsmith.io\/index.php\/wp-json\/wp\/v2\/media?parent=166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}