7 min read

What 214 alerts a day actually contain

We sorted a month of alerts from 40 customers by what they turned out to be. Most of them were the same six things.

Dana Reyes

Lead analyst

var(--variable-YhzOYHZ6N)

A 400-person company with four log sources sends Wardell a median of 214 alerts a day. Before grouping, that is the number a small security team would have to look at.

Six patterns make up most of the noise

Across 40 customers in August, six patterns made up 81 percent of alerts: VPN logins from new cities, scheduled admin jobs, developer tools calling cloud APIs from home networks, bulk downloads by the finance team at month end, password resets during onboarding, and scanners hitting the WAF.

None of them are dangerous on their own. All of them can hide the one that is.

Grouping is where the time goes back

When alerts that share a user, a host or an app become one case, 214 alerts turn into about nine cases a day. The rest close themselves with a note that says why, and stay searchable.

The practical result for a team of two is simple: the Monday queue fits in a morning.

Send us one week of logs. We send back what we found.

Connect one source with a read-only key. Within 48 hours you get a written report of what Wardell would have caught. No contract, and you can disconnect at any time.

Use this free template

Create a free website with Framer, the website builder loved by startups, designers and agencies.