JELAJAH SOC
YO

Engineering

Platform health & capacity

The detection platform is itself an asset that fails. Saturated ingest nodes drop events, full hot tiers shorten your search window, and both failures look like a quiet day on the dashboards.

Cluster state

Degraded

2 of 6 nodes above threshold

Peak ingest

15.2k EPS

Friday 09:00–10:00

Search latency p95

1.9 s

90-day range queries

Hot tier used

71%

8.4 of 12 TB

Nodes

Resource pressure by role.

NodeRoleCPUMemoryDiskState
ingest-01Ingest
62
58
44
Healthy
ingest-02Ingest
81
74
47
Degraded
index-01Index / hot
55
69
71
Healthy
index-02Index / warm
31
47
83
Degraded
rules-01Correlation
77
61
22
Healthy
api-01Query / API
40
52
18
Healthy

Daily volume & peak rate

Mon590G
Tue612G
Wed640G
Thu628G
Fri671G
Sat402G
Sun388G

Weekday volume runs roughly 60% above the weekend. Size ingest for the Friday peak, not the weekly average, or you will lose events exactly when the estate is busiest.

Retention tiers

How far back you can actually investigate.

  • Hot · 14 days

    8.4 / 12 TB

    Live triage and dashboards

  • Warm · 90 days

    22.1 / 30 TB

    Investigation and hunting

  • Cold · 365 days

    61.7 / 120 TB

    Compliance and retrospective hunts

Symptoms that mean platform, not attackertriage
  • Event volume drops estate-wide at a round-numbered time — that is a collector, not calm.
  • Alerts arrive in bursts after a gap — a queue drained, so your timestamps are late.
  • A saved search that always returned results now returns none — check parsing before you celebrate.
  • Searches slow only on long ranges — warm-tier pressure, not a query problem.

Learn this capability

Hands-on labs that build the technique behind this workspace. Skills transfer to any mainstream SIEM.