Open alerts by severity
barSpot whether the queue is critical-heavy before you start.
Monitoring & analytics
A dashboard is an argument, not a wall of charts. Each board here is built for one audience and one decision — read the note under every panel to learn why it earns its space.
Boards
6
Panels
24
Fastest refresh
30s
shift overview
Audiences served
4
L1, L2, engineering, leadership
Everything a starting shift needs in one screen: queue pressure, ageing alerts and the loudest rules.
Spot whether the queue is critical-heavy before you start.
Anything older than 30 minutes needs a reason.
A single rule above 30% of volume usually needs tuning.
A sudden drop means a feed died, not a quiet day.
Building your own: name the decision first, then choose the fewest panels that support it. If a panel has never changed anyone's action, delete it — visual clutter costs attention during exactly the minutes when attention matters most.
Hands-on labs that build the technique behind this workspace. Skills transfer to any mainstream SIEM.
Advanced · Theory · 20 min
SOC metrics that matter
You report to the CISO monthly. Choosing the wrong metrics drives the wrong analyst behaviour.
Foundation · Simulation · 40 min
Triage 20 alerts against the clock
It is 09:00 and the queue built up overnight. You have a shift's worth of alerts and limited time. Work the queue: confirm what matters, dismiss what does not, and escalate anything that is beyond L1.
Intermediate · Theory · 16 min
Detection quality principles
You own the detection catalogue. Every rule you deploy costs analyst attention, so quality is measured in outcomes, not count.