The situation
This U.S. regional transit agency operates a multi-site network around the clock across corporate IT and operational systems. Splunk is the primary SIEM, supported by Microsoft Defender, Microsoft Sentinel, Entra ID, and ManageEngine. Alaris was already returning an investigated verdict on every alert. The remaining gap was confidence to close: teaching the system what this specific team knew was benign and what was merely repetitive.
The team already knew which alerts were routine or benign, but that judgment lived in analysts' heads. Roughly four in ten alerts still reached a person, including repeated cases the team had effectively settled before.
Alaris encoded the team's knowledge into pre-queue Splunk workflows, duplicate clustering, and a tenant-specific auto-close policy that closes confident calls on evidence.
The Pressure: Known Noise Still Required a Person
The team could recognize routine service-account activity, the same rule firing on the same host, and known-benign patterns particular to a transit environment. Because that judgment had not yet been encoded, those alerts still landed on a person.
Before this work, approximately 40% of alerts reached a person. At a 60% auto-close rate, four in ten alerts required review; at 98%, fewer than one in forty does.
Repetition compounded the problem. The same benign events arrived repeatedly, and correlated alerts pulled otherwise-clear cases into review. Analysts spent time re-deciding cases they had effectively settled long ago. Detection was not the issue; the missing layer was a safe way to operationalize what the team already knew.
The Deployment: Move Analyst Judgment Into Policy
Alaris worked directly in the queue with the agency's analysts, cataloging what was benign in their environment and what continued to repeat. Each pattern became something the platform could evaluate and act on.
Filter known-benign alerts before intake
Pre-queue workflows in Splunk remove alerts the team already knows are benign at the source, so they never consume analyst attention.
Investigate recurring alerts once
A new alert is compared with recent open alerts from the same source across a 60-minute look-back. Title similarity and shared entities identify likely matches, and an agent confirms genuine duplicates before collapsing them beneath a parent case. The cluster is investigated once.
Tune autonomous close to the environment
With benign and repetitive activity handled, the auto-close policy was tuned per tenant. In balanced mode, the agent can close alerts up to medium severity at 75% confidence, judging each case on its own evidence rather than inheriting suspicion from neighboring alerts.
Before: approximately 60%
Before: approximately 4 in 10
Previously reached the queue
Previously reviewed individually
The Result: A Queue Reserved for Real Judgment
At steady state, alerts the team has established as benign are filtered before intake, repetitive events collapse into a single case, and the agent closes what the evidence supports. What reaches an analyst is a short list of cases that genuinely merit judgment.
- 01
Benign patterns are removed in Splunk before they reach the queue.
- 02
Recurring and duplicate alerts collapse into one case that the agent investigates once.
- 03
The auto-close policy reflects the team's own judgment and remains tunable per tenant as trust builds.
Methodology: figures reflect a steady-state window, are platform-reported, and are measured against the deployment record. Detection did not change; the team's judgment now lives in the system.
Entra ID
Manage Engine