[logs] too many false alarms

Jon Stearley jrstear at sandia.gov
Thu Jan 24 15:04:43 PST 2008


what false alarm rate do you tolerate for your current monitoring  
system?  is 1 false alarm in 4 ok?  1 in 10?  1 in 100?

a related question is: what false alarm rate must anomaly detection  
systems achieve to be useful?

i know this is person/site/situation/etc specific, and welcome any  
ballpark figures or experiences.  thanks.

-jon stearley




More information about the LogAnalysis mailing list