Feed: running
drag to pan · wheel/pinch to zoom

SOAR Alert Correlation Engine 2D: Union-Find Incident Clustering

Modern Security Orchestration, Automation and Response platforms spend most of their value not on running playbooks but on the step before them: deciding which of the thousand raw alerts a SIEM fires per hour actually describe the same incident. This 2D build renders that correlation engine as a flat, pannable alert field — a live stream of alerts spawns at the top and drifts toward its incident cluster, each one scored against its recent neighbours on shared source subnet, shared target asset and time proximity, and merged via union-find the moment the score clears an adjustable threshold. Tune the arrival rate, correlation threshold, dedup window and rule-weighting mode and watch the dedup-reduction and incident-count readouts respond in real time, plus a rolling reduction-history strip along the bottom — the same trade-off a SOC analyst tunes in Splunk Phantom, Cortex XSOAR or Microsoft Sentinel to keep alert volume from drowning the response team.