Security event analytics fails quietly when people stop believing alerts. A rule that labels every mobile retry as credential stuffing will bury real abuse. Analysts learn to dismiss the stream, and the next true positive arrives into a culture of skepticism.
Collect examples of alerts that wasted time. Note the application, the user population, and the environmental quirk — corporate NAT ranges, partner batch jobs, or health-check endpoints that look like scanners. Feed those quirks back into rule conditions as explicit exclusions or thresholds.
Measure noise by analyst minutes, not only by count. Ten easy false positives may cost less than one ambiguous alert that requires three teams to decode. Prioritize tuning where investigation effort concentrates.
After each tuning pass, re-test against a retained sample of known-good and known-bad windows. Document why each change was made so future engineers do not undo a hard-won exclusion during a hurried release.