SIEM
Security information and event management: collect, normalise, correlate, alert. Useless if nobody owns the queue.
A SIEM is a pipeline plus a queue. Logs in, detections out, humans in the middle. Volume is not coverage.
Tune until a real event is distinguishable from noise. Retire rules that have not earned their keep. Name an owner for after-hours.
If you cannot say which detections map to which ATT&CK techniques you care about, you have a data lake with a siren.
