Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

ManageEngine: Reducing Alert Fatigue with Smart Thresholds in Log360

Manage Engine
07/25/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Cyber threats are evolving constantly, with attack patterns shifting based on new vulnerabilities and tactics. So to stay ahead, analysts need timely and accurate alerts to remain aware of potential threats. However, static thresholds that trigger alerts based on a fixed limit often lead to false positives or missed threats. So a rigid threshold may fail to detect a slow, stealthy attack or trigger unnecessary alerts for normal fluctuations. And this is where adaptive or smart thresholds come in. So what are smart thresholds? Smart thresholds dynamically adjust alert conditions based on real-time analysis and historical data. And unlike static thresholds, they continuously learn from system activity, adapting to changes in user behavior, network traffic, and application usage. This approach enhances threat detection while reducing false positives and negatives. So here's how it works. The solution establishes a baseline of normal activity, adjusts dynamically to deviations, then detects anomalies against this baseline. It triggers alerts only when deviations indicate potential threats. It utilizes machine learning to recognize patterns. It then incorporates a feedback loop to refine accuracy over time. Now let me demonstrate this feature using Event Log Analyzer, which is also a component of Lock360. Account lockouts are a common occurrence in any organization, especially during periodic password update cycles. But during these windows, the number of failed login attempts can skyrocket, which overwhelm the security team with alerts that are mostly harmless. With Lock360's smart threshold feature, you can filter out these expected spikes and focus only on anomalies that truly need investigation. Now let me walk you through how to set it up. Go to the Alerts tab and click Add Alert Profile. Set the alert profile name as Abnormal Account Lockouts, or name it as you see it fit. Set the severity to Critical or Troubled, depending on your organization's risk policy. Choose the appropriate log source, then choose Account Lockout from the predefined alert criteria. This ensures the alert is tied to real-time account lockout events captured from SQL Server logs. Modify the alert message to provide more context, if needed. Now it's time to set the threshold. Instead of setting a fixed number of lockouts, select the Smart Threshold option. Lock360 will utilize machine learning to analyze historical account lockout patterns for each user and adjust the threshold dynamically. For example, if a user typically experiences 0-1 lockouts a month and suddenly hits 5 lockouts in 10 minutes, Lock360 will flag it. But if dozens of users are being locked out during a known password reset period, the system will adjust the threshold to allow for more lockouts, preventing a flood of alerts. You can specify the timeframe for monitoring, ensuring that Smart Threshold learns the baseline activity for that period. Finally, click Save Profile. Lock360 will now start learning from historical data, refining thresholds per user or peer group, and ensuring alerts are contextually relevant. By using Smart Thresholds during periods like organization-wide password resets, Lock360 ensures that your security team isn't bogged down by alert noise and instead remains focused on identifying real threats like targeted account compromise or insider misuse. If you'd like to know more about Lock360 and how it works, please contact our technical experts today.

TL;DR

  • Static thresholds in SIEM systems generate excessive false positives during normal events like password resets while missing slow, stealthy attacks that stay below fixed limits.
  • Log360's smart thresholds use machine learning to establish behavioral baselines per user or peer group, dynamically adjusting alert conditions based on real-time and historical activity patterns.
  • The feature filters out expected spikes during operational windows while flagging genuine anomalies, allowing security teams to focus on real threats like targeted account compromise rather than routine noise.

Summary

This demonstration showcases Log360's smart threshold feature, which addresses a critical challenge in security operations: alert fatigue caused by static threshold configurations. Traditional SIEM alerting relies on fixed limits that often generate false positives during normal operational events like password reset cycles, while simultaneously missing stealthy attacks that fall below arbitrary thresholds. Log360's adaptive approach uses machine learning to establish behavioral baselines for individual users and peer groups, dynamically adjusting alert conditions based on real-time analysis and historical patterns. The video walks through a practical implementation scenario focused on account lockout monitoring, demonstrating how to configure smart thresholds that distinguish between expected spikes during password update windows and genuine security anomalies requiring investigation. By continuously learning from system activity and incorporating feedback loops, the solution aims to reduce alert noise while improving detection accuracy for targeted account compromise and insider threats.

Chapters

0:00 - Introduction
0:47 - What Are Smart Thresholds
1:11 - How Smart Thresholds Work
1:34 - Product Demonstration

Key Quotes

0:29 "So a rigid threshold may fail to detect a slow, stealthy attack or trigger unnecessary alerts for normal fluctuations."
0:52 "Smart thresholds dynamically adjust alert conditions based on real-time analysis and historical data."
2:58 "For example, if a user typically experiences 0-1 lockouts a month and suddenly hits 5 lockouts in 10 minutes, Lock360 will flag it."

FAQ

How do smart thresholds differ from traditional static thresholds in SIEM alerting?

Smart thresholds dynamically adjust alert conditions based on real-time analysis and historical data, establishing behavioral baselines that adapt to normal fluctuations. Static thresholds use fixed limits that often trigger false positives during expected events or miss stealthy attacks that fall below arbitrary thresholds.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • SIEM
  • Demo
  • Getting Started
  • Threat Intelligence
  • Alert Fatigue Reduction
  • Adaptive Thresholds
  • Machine Learning in SIEM
  • Account Lockout Monitoring
  • Behavioral Baseline Analysis
  • False Positive Reduction
  • Anomaly Detection
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: ManageEngine: Reducing Alert Fatigue with Smart Thresholds in Log360

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    • Sep
                      23

                      Understanding Invisible Data Risks and Enhancing Your Protection Strategies

                      09/23/202601:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 08/27/2026
                        01:00 PM
                        08/27/2026
                        Becoming Agent Ready with Cyera: Essential Strategies and Insights
                        https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                      • 08/27/2026
                        01:00 PM
                        08/27/2026
                        Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                        https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/03/2026
                        01:00 PM
                        09/03/2026
                        Verge.io: Can You Afford Your Next Storage Refresh?
                        https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                      • 09/23/2026
                        01:00 PM
                        09/23/2026
                        Understanding Invisible Data Risks and Enhancing Your Protection Strategies
                        https://www.truthinit.com/index.php/channel/2087/understanding-invisible-data-risks-and-enhancing-your-protection-strategies/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      • 11/19/2026
                        01:00 PM
                        11/19/2026
                        360View: Govern, Secure & Recover Your Microsoft 365 Environment
                        https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version