SOAR Alert Correlation Engine 2D: Union-Find Incident Clustering
A 2D top-down view of a SOAR correlation engine deduplicating a live SIEM alert stream: drag to pan and scroll to zoom the alert field, tune arrival rate, correlation threshold, dedup window and rule weighting, and watch union-find merge raw alerts into incident clusters in real time.
Modern Security Orchestration, Automation and Response platforms spend most of their value not on running playbooks but on the step before them: deciding which of the thousand raw alerts a SIEM fires per hour actually describe the same incident. This 2D build renders that correlation engine as a flat, pannable alert field — a live stream of alerts spawns at the top and drifts toward its incident cluster, each one scored against its recent neighbours on shared source subnet, shared target asset and time proximity, and merged via union-find the moment the score clears an adjustable threshold. Tune the arrival rate, correlation threshold, dedup window and rule-weighting mode and watch the dedup-reduction and incident-count readouts respond in real time, plus a rolling reduction-history strip along the bottom — the same trade-off a SOC analyst tunes in Splunk Phantom, Cortex XSOAR or Microsoft Sentinel to keep alert volume from drowning the response team.
A pannable, zoomable 2D field of raw SIEM alerts streaming in and drifting toward shared incident clusters, scored against recent neighbours on subnet, asset and time proximity and merged via union-find the moment the score clears an adjustable threshold, with a rolling dedup-reduction sparkline tracking the workload cut in real time.
2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install