The situation
This organization is one of the ten largest federally qualified health centers in the country, operating more than 90 care sites and serving hundreds of thousands of patients each year. Its small security team is responsible for detection, response, and audit readiness across a footprint that never closes. Sophos covered the endpoint, ManageEngine handled tickets, and Demisto carried hand-built SOAR playbooks—but Sophos alone produced about 30,000 alerts every week.
Sophos generated roughly 30,000 alerts each week, predominantly repeat events from a small set of service accounts and noisy rules. The volume exceeded team capacity, slowed the platform, and made ticket synchronization unreliable.
Alaris connected read-only, traced the sources of noise with the analysts, then introduced conservative connector filters, duplicate clustering, and account-specific auto-close policies as trust grew.
The Pressure: 1,000 Hours of Triage for a Team With 120
The vast majority of the 30,000 weekly alerts were recurring or duplicate events: the same rule on the same host or the same service account triggering the same benign check repeatedly. Most alerts could not be meaningfully investigated within the team's available capacity.
At only two minutes per alert, 30,000 alerts require 1,000 hours of triage each week. The team had approximately 120 hours available.
The volume also slowed the platform and made ManageEngine synchronization brittle, creating ticket lag and weakening confidence that the system of record was current. A peer healthcare breach, board requests for evidence of continuous coverage, and an upcoming HIPAA audit added urgency.
The Deployment: Conservative First, Autonomous as Trust Builds
Alaris connected read-only and worked with the SOC analysts to identify which service accounts, users, and detection rules produced the same benign events. The rollout began with simple connector filters and grouping, then expanded as each policy proved safe.
Collapse repetition before it reaches the queue
New alerts are compared with recent open alerts from the same source, matched on title similarity and shared entities, and checked by an agent before genuine duplicates collapse beneath a parent. The agent investigates the cluster once; the analyst sees one item instead of twenty.
Review account activity once a week
Known-benign account activity closes automatically and appears in a single weekly recap. The team reviews unique occurrences rather than thousands of individual tickets. Demisto playbooks were also rebuilt as simpler agent workflows with evidence-based conclusions.
Before: approximately 30,000 weekly
Investigated once
Before: approximately 90 hours
Before: brittle under load
The Result: The Same Intake, a Queue of New Information
At steady state, recurring Sophos events collapse before reaching a person, benign service-account activity closes itself and appears in a weekly recap, and the ManageEngine record remains current. The team spends its limited hours on alerts that are genuinely new.
- 01
Benign account activity closes automatically and is reviewed once in a concise weekly recap.
- 02
Recurring alerts cluster under one parent, allowing one investigation rather than twenty.
- 03
Reasoning mode, auto-close policy, and clustering remain tuned per account and can be widened as trust builds.
Methodology: figures reflect a 30-day post-deployment window, are platform-reported, and are measured against the deployment record. Ingest volume remained unchanged by design: Alaris did not stop Sophos from firing; it answered what fired.
Manage Engine
Demisto