# Endpoint security, Security

Published articles for Endpoint security, Security.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Reducing false positives with automated SIEM investigations from Elastic and Tines

DevFeed: [Reducing false positives with automated SIEM investigations from Elastic and Tines](<https://devfeed.tech/articles/reducing-false-positives-with-automated-siem-investigations-from-elastic-and-tines-4823.md>)

Original publisher: [Read original article](<https://www.elastic.co/blog/false-positives-automated-siem-investigations-elastic-tines>)

Author: Aaron Jewitt

Published: 2024-05-31T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Blog - Elasticsearch, Kibana, and ELK Stack](<https://devfeed.tech/sources/elastic-blog-elasticsearch-kibana-and-elk-stack.md>)

Topics: [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [SOC](<https://devfeed.tech/topics/soc.md>), [Security](<https://devfeed.tech/topics/security.md>), [elasticsearch](<https://devfeed.tech/topics/elasticsearch.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [analysts](<https://devfeed.tech/tags/analysts.md>), [api](<https://devfeed.tech/tags/api.md>), [automated-threat-protection-anomaly-detection-cybersecurity-network-visibility-security-analytic](<https://devfeed.tech/tags/automated-threat-protection-anomaly-detection-cybersecurity-network-visibility-security-analytic.md>), [aws](<https://devfeed.tech/tags/aws.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [elastic](<https://devfeed.tech/tags/elastic.md>), [endpoint-security-security](<https://devfeed.tech/tags/endpoint-security-security.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [logs](<https://devfeed.tech/tags/logs.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [soc](<https://devfeed.tech/tags/soc.md>), [token](<https://devfeed.tech/tags/token.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

Elastic's InfoSec team uses Tines to automate initial SIEM alert investigations, helping reduce false positives and analyst fatigue. The workflow queries Elasticsearch using alert data such as source.ip, closes alerts associated with trusted devices or known benign activity, and escalates cases that cannot be resolved automatically.

### Source excerpt

Discover how Elastic's InfoSec team saves thousands of hours per month by using Tines to automate SIEM alert investigations while reducing false positives and detect compromised accounts.