Skip to main content

Scenario insights

Updated over 6 months ago

Scenario Insights provide feedback on the effectiveness and quality of your monitoring scenarios, helping you improve operational efficiency and stay compliant. These insights allow you to:

  • Identify which scenarios are generating the most alerts.

  • Evaluate individual scenarios by analysing their true positive alert rate and meaningful alert rate.

❗️Insights are calculated once daily, typically at night. They are not real-time statistics.


Scenario list insights

Most alerts generated (last 30 days)

  • Shows the top 5 scenarios generating the most alerts over the last 30 days.

  • Data dynamically updates based on applied filters (e.g., filtering by Type = Periodic), allowing you to analyse scenarios specifically within the filtered results.

    • Note: Insights update dynamically based on filters (alerting entity, type, status, or category). However, they do not adjust based on the search results (e.g., searching for scenarios by name with keywords like "high value" will not affect the insights).

Displayed Metric

  • Displays the percentage of alerts generated by each scenario compared to the total alerts generated by the scenarios in the current view over the last 30 days.

    • Formula: (Alerts generated by Scenario X (across all versions)/ Total alerts generated by the filtered scenarios in the last 30 days) × 100%


Specific Scenario insights

These metrics provide detailed insights into the quality and effectiveness of individual scenarios.

True positive rate

  • The percentage of true positive alerts from all closed alerts generated by the scenario (across all versions).

    • Formula: (True positive alerts / Total closed alerts) × 100%

Meaningful alert rate

  • The percentage of meaningful alerts from all closed alerts generated by the scenario (across all versions).

    • Formula: (Meaningful alerts / Total closed alerts) × 100%

An alert is classified as meaningful if it meets any of the following criteria:

  • Assignees: assigned to more than one user during the alert's history

  • Notes: has two or more notes

  • Files: has one or more files attached

  • Bridge investigations: a Bridge investigation is created from the alert

  • Statuses: has had at least one status that was neither NEW nor a final status during the alert's history

  • True positive: marked with a true positive status

How to read the metrics

  • Current Period: The first percentage represents the last 30 days.
    Example: On 10th December, this covers the period 10th November – 9th December.

  • Comparison Period: The second percentage represents the change compared to the previous 90 days.
    Example: For the same date, the comparison covers 12th August – 10th November.

    • NB: The 30-day and 90-day periods do not overlap.

Did this answer your question?