skip to content

Your intel analyst wants a whole subscribed indicator feed alerting in the SIEM and you have one analyst — what do you agree to?

level: principalimportance: should knowfreq 44%

answer

  1. not a quality argument, a capacity one
  2. enrichment by default, alerting by exception
  3. small, high-confidence, expiry-dated, owned
  4. who re-confirms is the lever
  5. show the trade on your own side

basics

~20 s

Take the feed as enrichment on records and alerts by default, and let only a small, high-confidence subset alert, with an expiry date and a named owner who re-confirms it. The constraint is your analyst's week.

solid answer

~50 s

I would separate two decisions people run together. Whether the feed is good is not the question; assume it is. The question is what claim each shape of use makes on the only triage capacity I have. So the whole feed lands as enrichment — records and alerts get tagged, which costs nothing per week and makes the analyst faster when something else fires. A small subset gets to alert: entries tied to activity we believe is aimed at us, in the tens or low hundreds, each with an expiry date and a named owner who re-confirms them. If the intel analyst will not own that expiry, the list does not ship — an entry nobody re-confirms is one that pages my only analyst about infrastructure that changed hands months ago. And I would make the trade two-sided by retiring the artefact rules we keep rewriting.

go deeper

for a junior

Know that every alerting rule costs someone time every week, and that a match list needs a date and an owner. Be able to say why enrichment is cheaper than alerting.

for a middle

Explain the two shapes a feed can take — tagging records and alerts, versus firing its own alerts — and the conditions under which a match list is allowed the second one.

for a senior

Show you would enumerate what the alerting subset costs per week before agreeing, and that you would retire your own artefact rules as part of the same trade rather than only constraining someone else.

for a principal

Own the negotiation: make ownership of expiry the condition of the alerting slot, agree the measurements that will settle the next review, and keep the argument on capacity rather than on whose intel is better.

## Name the real constraint out loud The conversation goes wrong when it becomes an argument about the feed. Assume the feed is excellent. The scarce resource in this room is not indicator quality, it is one analyst's week, and every alerting rule you accept takes a slice of it that you cannot get back. Framing the decision that way turns a taste dispute into a capacity conversation, and capacity conversations can be settled with numbers. So the position is not "no". It is: the feed comes in, and the *shape* of its use is what we negotiate. ## Default shape: enrichment, not alerting Most of a large feed's value is realised without any rule at all. Tag records and existing alerts with what the feed knows, so when something else fires the analyst sees the context immediately instead of pivoting to a portal. This costs nothing per week when nothing happens, adds no scheduled scans, and — crucially — never converts somebody else's collection into your queue. It also puts the feed where the analyst already works, which is the difference between intel that changes a verdict and intel that sits in a subscription nobody opens. ## Where a match list still earns an alerting slot Match lists are not amateur hour. A short one is among the cheapest things a small team owns: near-zero authoring cost, zero cost while silent, and a fast, defensible close when it hits. The conditions that make it earn its slot are specific: - **Small** — tens to low hundreds of entries, not tens of thousands. - **High confidence** — entries tied to activity you have a concrete reason to think is aimed at your estate, not everything the feed carries. - **Expiry-dated** — every entry has a date after which it leaves alerting automatically, so the list shrinks by default rather than growing by default. - **Owned by name** — a person, not a team, re-confirms entries on a stated cadence. That last condition is the organisational lever, and it is the one to hold. Offer the intel analyst the alerting slot on the explicit condition that they own the expiry and re-confirmation. If they take it, you have a maintained list and a shared cost. If they will not, that is itself the answer — an entry nobody will re-confirm is an entry that wakes your only analyst about a domain that changed hands six months ago, and the person who declined to maintain it will not be the one triaging it. ## Make the portfolio trade visible This decision is a trade, not a refusal, and it works far better when you show what you are giving up on your own side of the table. The artefact rules your team keeps rewriting — the ones matching a fronted hostname or an edge address that moves every few days — get retired rather than rewritten again. What is still useful from them folds into exactly the narrow, expiry-dated list described above. The maintenance that frees up goes into behavioural coverage of the same technique, which keeps working when the infrastructure moves. The intel analyst gets a real alerting slot and a maintained list; you get out of a rewrite treadmill; the estate ends up better covered. Nobody has to lose the argument. ## Agree the measurements before the rollout Settle in advance what will decide the next version of this conversation, so it is not re-litigated on impressions: - **Alerts per week per rule**, so a list that quietly starts producing volume is visible. - **How many alerting entries are past their expiry**, which measures whether the ownership commitment survived contact with reality. - **Verdicts that the enrichment changed** — cases where the tag on an alert altered what the analyst concluded. This is the honest way to show the enrichment path is worth having, and it does not require any rule. - **Rewrites per rule per quarter** on the behavioural side, which is what justified the trade. ## What not to do Do not accept the whole feed as alerting rules with an intention to tune later; on a one-analyst team, later never comes, and the first noisy week teaches everyone to skim the queue, which is a durable loss. Do not refuse the feed outright either — that reads as territorial and throws away real value that costs you nothing in the enrichment shape. And do not argue about the feed's contents; that is a different conversation with a different owner, and holding it here is how you lose the capacity argument you were actually going to win.

  • The intel analyst says filtering the feed means you will miss things. How do you answer?
    Agree, and put the miss next to its cost. Nothing is discarded — the whole feed still tags records and alerts, so it is present at triage. What is filtered is the subset allowed to consume triage capacity. Then offer the measurement: verdicts changed by enrichment, versus alerts per week per rule, so the next review argues from numbers rather than from fear of missing something.
  • What do you do when nobody will own the expiry and re-confirmation of the alerting list?
    Then it does not alert; it stays as enrichment. This is not punishment, it is the honest consequence: an unmaintained alerting list becomes a source of pages about infrastructure that has changed hands, and the person who declined the maintenance will not be triaging those. Making ownership the condition puts the cost next to the request.
  • Six months on, how do you tell whether this arrangement worked?
    Look at three numbers. How many alerting entries are past expiry, which tests whether the ownership commitment held. Alerts per week per rule, which catches a list quietly turning noisy. And how many verdicts the enrichment actually changed, which is the only evidence that the unfiltered part of the feed is earning anything.

Every alerting rule is a standing appointment in your analyst's week. You can accept a few and keep them, or accept forty thousand and keep none.

saying these in an interview costs you the question

  • Argues about the feed's quality instead of capacity
  • Accepts the full feed as alerting, intending to tune later
  • Refuses the feed outright and loses free enrichment value
  • Creates a match list with no expiry or owner
  • Assumes more alerting rules means more coverage
  • Leaves the trade one-sided by giving up nothing

context