CISO dinner in Vancouver, Sept 9RSVP
Alaris
Pricing

Autonomous security operations · Public sector

Built With Their Team: 98% of Alerts Now Close on Their Own

How a U.S. regional transit agency encoded analyst judgment, collapsed recurring alerts, and raised autonomous close from roughly 60% to 98%.

SOC Efficiency4 min readEthan GlennyJuly 2026United States
Open the 4-page PDF

Outcomes · platform-reported

98%Autonomous Close RateUp from approximately 60%
~2%Alerts Reaching an AnalystFewer than 1 in 40
0SOC Headcount AddedSame team, shorter queue
20:1Duplicates CollapsedInvestigated once, not twenty times
IndustryPublic sector / regional transit
EnvironmentMulti-site transit network
Integrations in scope

01

The situation

This U.S. regional transit agency operates a multi-site network around the clock across corporate IT and operational systems. Splunk is the primary SIEM, supported by Microsoft Defender, Microsoft Sentinel, Entra ID, and ManageEngine. Alaris was already returning an investigated verdict on every alert. The remaining gap was confidence to close: teaching the system what this specific team knew was benign and what was merely repetitive.

The pressure

The team already knew which alerts were routine or benign, but that judgment lived in analysts' heads. Roughly four in ten alerts still reached a person, including repeated cases the team had effectively settled before.

The operating change

Alaris encoded the team's knowledge into pre-queue Splunk workflows, duplicate clustering, and a tenant-specific auto-close policy that closes confident calls on evidence.

02

The Pressure: Known Noise Still Required a Person

The team could recognize routine service-account activity, the same rule firing on the same host, and known-benign patterns particular to a transit environment. Because that judgment had not yet been encoded, those alerts still landed on a person.

Before this work, approximately 40% of alerts reached a person. At a 60% auto-close rate, four in ten alerts required review; at 98%, fewer than one in forty does.

Repetition compounded the problem. The same benign events arrived repeatedly, and correlated alerts pulled otherwise-clear cases into review. Analysts spent time re-deciding cases they had effectively settled long ago. Detection was not the issue; the missing layer was a safe way to operationalize what the team already knew.

03

The Deployment: Move Analyst Judgment Into Policy

Alaris worked directly in the queue with the agency's analysts, cataloging what was benign in their environment and what continued to repeat. Each pattern became something the platform could evaluate and act on.

Filter known-benign alerts before intake

Pre-queue workflows in Splunk remove alerts the team already knows are benign at the source, so they never consume analyst attention.

Investigate recurring alerts once

A new alert is compared with recent open alerts from the same source across a 60-minute look-back. Title similarity and shared entities identify likely matches, and an agent confirms genuine duplicates before collapsing them beneath a parent case. The cluster is investigated once.

Tune autonomous close to the environment

With benign and repetitive activity handled, the auto-close policy was tuned per tenant. In balanced mode, the agent can close alerts up to medium severity at 75% confidence, judging each case on its own evidence rather than inheriting suspicion from neighboring alerts.

98%Agent Auto-Close Rate

Before: approximately 60%

<1 in 40Analyst Queue

Before: approximately 4 in 10

Pre-filteredKnown-Benign Alerts

Previously reached the queue

One caseDuplicate Review

Previously reviewed individually

04

The Result: A Queue Reserved for Real Judgment

At steady state, alerts the team has established as benign are filtered before intake, repetitive events collapse into a single case, and the agent closes what the evidence supports. What reaches an analyst is a short list of cases that genuinely merit judgment.

  1. 01

    Benign patterns are removed in Splunk before they reach the queue.

  2. 02

    Recurring and duplicate alerts collapse into one case that the agent investigates once.

  3. 03

    The auto-close policy reflects the team's own judgment and remains tunable per tenant as trust builds.

Methodology: figures reflect a steady-state window, are platform-reported, and are measured against the deployment record. Detection did not change; the team's judgment now lives in the system.