Back to Blog
Security Operations
9 min read

SIEM Tuning for Hospitals: Reducing Noise Without Missing Threats

A SIEM producing 4,000 alerts a day is producing none, because nobody reads 4,000 alerts. Suppressing safely, measuring whether tuning worked, and the rules worth keeping noisy.

GuardsArm Team

Security Experts

December 26, 2025

SIEM tuning

A SIEM that raises four thousand alerts a day raises none, because no team reads four thousand alerts. They read the first fifty, develop a reflex for the recurring ones, and stop looking. The dangerous part is not the noise itself — it is that the noise trains analysts to dismiss the category the real alert will arrive in.

Alert fatigue
The failure mode is not missed alerts but dismissed ones
Clinical noise
Shared workstations and legacy protocols generate volumes no corporate rule set expects
Tune, do not delete
A suppressed alert should still be searchable; a deleted rule is a blind spot

Why hospital SIEMs are noisier than most

Rule sets are written for corporate environments and then dropped into a clinical one, where several normal behaviours look exactly like attacks:

  • Shared workstations produce rapid user switching that resembles credential stuffing
  • Roaming clinicians sign in from a dozen locations in a shift — impossible travel, by the rule's definition
  • Legacy medical devices speak SMBv1 and unencrypted protocols as designed
  • Night-shift access patterns trip "unusual hours" rules continuously
  • Break-glass is a legitimate, expected privilege escalation
  • Interface engines move enormous volumes of data between systems, which is the same shape as bulk exfiltration

Each of these needs a tuned rule, not a disabled one.


Triage the backlog before touching anything

Start by finding out where the volume actually comes from. It is almost never evenly distributed.

Where a typical hospital SIEM alert volume comes fromIllustrative distribution showing alert volume concentrated in a handful of rules.Top 1 rule1450Usually one misconfigured or untuned detectionRules 2-51180Clinical behaviour misread as attackRules 6-20620Mixed; some worth keepingEverything else310The long tail, often the useful part
Illustrative. Fixing the top five rules usually removes most of the volume.

Fixing the top five rules typically removes the majority of the noise, which buys the credibility to do the slower work.


Suppress safely

The difference between tuning and creating a blind spot is precision and visibility.

BadGood
Disable the ruleAdd a narrow exclusion for the known-benign condition
Exclude a whole subnetExclude a named service account on a named host, for a named process
Silent suppressionSuppressed events still written and searchable, just not alerting
PermanentExclusion has an owner and a review date
UndocumentedReason recorded on the exclusion itself
Never exclude by source IP range alone
The broad exclusion written to silence a noisy clinical VLAN is the one an attacker benefits from later, because that VLAN is exactly where a compromised device will sit. Narrow the exclusion to the specific benign behaviour, not the location.

Rules worth keeping noisy

A handful of detections should alert every time even though they fire often, because the cost of missing one is high and the review is cheap:

  • Break-glass and emergency access use
  • Access to a VIP or employee medical record
  • Any authentication by a disabled or terminated account
  • Changes to audit logging configuration
  • New privileged group membership
  • Backup deletion or retention policy change

If these are noisy, the answer is to reduce the underlying behaviour, not the alerting.


Measure whether tuning worked

Alert count going down is not success on its own — you can achieve that by switching everything off. Pair volume with quality:

MetricWhat it tells you
Alerts per analyst per shiftWhether the queue is humanly workable
True positive rateWhether the remaining alerts are worth reading
Mean time to triageWhether analysts can keep up
Detection coverage by ATT&CK techniqueWhether tuning created blind spots
Alerts closed without investigationThe honest measure of fatigue

That last one is the most useful and least reported. A rising rate of alerts closed with no investigation notes means the queue has stopped being read, regardless of what the volume chart says.


Coverage, so tuning does not become erosion

Map detections to MITRE ATT&CK techniques and re-check after each tuning cycle. The purpose is not a perfect matrix — it is to notice when a month of well-intentioned suppression has quietly removed your only detection for lateral movement.

SIEM tuning cycleVolume is baselined, the highest-volume rules are narrowed, coverage is re-mapped against ATT&CK and detections are validated before the next cycle.Baselinemeasure volumeTune top rulesnarrow exclusionsRe-map coverageATT&CK checkValidatetest detections fireRepeatmonthly cycle
The validate step means actually generating the behaviour and confirming the alert arrives.

Validation matters because a tuned rule can be silently broken. Generate the behaviour in a controlled way and confirm the alert fires. A detection nobody has tested since it was written is a hypothesis, not a control.

GuardsArm tunes healthcare SIEM deployments and maps detection coverage, including the clinical behaviours that generic rule sets consistently misread. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.