Detecting Noisy Alerts in Wazuh: What One Dashboard Told Us About Our Alert Volume
With a Wazuh cluster producing millions of alerts a month, this contribution builds a dashboard to answer a practical question: which rules create the noise, and which are safe to tune? Through five panels — a noise Pareto, top-triggering rules, noisy agents by hour, a rule burst heatmap, and a noise-vs-severity quadrant — the analysis moves tuning decisions from gut feeling to data: volume, level, agent spread, and timing. Includes exportable dashboard files for teams facing similar alert fatigue.