SIEM Tuning for Hospitals: Reducing Noise Without Missing Threats
A SIEM producing 4,000 alerts a day is producing none, because nobody reads 4,000 alerts. Suppressing safely, measuring whether tuning worked, and the rules worth keeping noisy.
GuardsArm Team
Security Experts
A SIEM that raises four thousand alerts a day raises none, because no team reads four thousand alerts. They read the first fifty, develop a reflex for the recurring ones, and stop looking. The dangerous part is not the noise itself — it is that the noise trains analysts to dismiss the category the real alert will arrive in.
Why hospital SIEMs are noisier than most
Rule sets are written for corporate environments and then dropped into a clinical one, where several normal behaviours look exactly like attacks:
- Shared workstations produce rapid user switching that resembles credential stuffing
- Roaming clinicians sign in from a dozen locations in a shift — impossible travel, by the rule's definition
- Legacy medical devices speak SMBv1 and unencrypted protocols as designed
- Night-shift access patterns trip "unusual hours" rules continuously
- Break-glass is a legitimate, expected privilege escalation
- Interface engines move enormous volumes of data between systems, which is the same shape as bulk exfiltration
Each of these needs a tuned rule, not a disabled one.
Triage the backlog before touching anything
Start by finding out where the volume actually comes from. It is almost never evenly distributed.
Fixing the top five rules typically removes the majority of the noise, which buys the credibility to do the slower work.
Suppress safely
The difference between tuning and creating a blind spot is precision and visibility.
| Bad | Good |
|---|---|
| Disable the rule | Add a narrow exclusion for the known-benign condition |
| Exclude a whole subnet | Exclude a named service account on a named host, for a named process |
| Silent suppression | Suppressed events still written and searchable, just not alerting |
| Permanent | Exclusion has an owner and a review date |
| Undocumented | Reason recorded on the exclusion itself |
Rules worth keeping noisy
A handful of detections should alert every time even though they fire often, because the cost of missing one is high and the review is cheap:
- Break-glass and emergency access use
- Access to a VIP or employee medical record
- Any authentication by a disabled or terminated account
- Changes to audit logging configuration
- New privileged group membership
- Backup deletion or retention policy change
If these are noisy, the answer is to reduce the underlying behaviour, not the alerting.
Measure whether tuning worked
Alert count going down is not success on its own — you can achieve that by switching everything off. Pair volume with quality:
| Metric | What it tells you |
|---|---|
| Alerts per analyst per shift | Whether the queue is humanly workable |
| True positive rate | Whether the remaining alerts are worth reading |
| Mean time to triage | Whether analysts can keep up |
| Detection coverage by ATT&CK technique | Whether tuning created blind spots |
| Alerts closed without investigation | The honest measure of fatigue |
That last one is the most useful and least reported. A rising rate of alerts closed with no investigation notes means the queue has stopped being read, regardless of what the volume chart says.
Coverage, so tuning does not become erosion
Map detections to MITRE ATT&CK techniques and re-check after each tuning cycle. The purpose is not a perfect matrix — it is to notice when a month of well-intentioned suppression has quietly removed your only detection for lateral movement.
Validation matters because a tuned rule can be silently broken. Generate the behaviour in a controlled way and confirm the alert fires. A detection nobody has tested since it was written is a hypothesis, not a control.
GuardsArm tunes healthcare SIEM deployments and maps detection coverage, including the clinical behaviours that generic rule sets consistently misread. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


