XSIAM Optimizer

Dashboard

Manage

CustomersConnections

Analyze

InsightsQuery StudioOptimizer

Output

ReportsAudit Log
XSIAM Onboarder 4.1.37

Insights

— Automated security assessments
|

API Health Status

System Health

Verify XSIAM instance is reachable and responding to API calls

Endpoint Coverage Analysis

System Health

Calculate connected vs total endpoint ratio and flag coverage gaps below 80%

Alert Volume Assessment

System Health

Analyze last 24 hours of alert volume and score based on alert counts

Overall Health Score

System Health

Composite health score combining API status, endpoint coverage, and alert volume

Endpoint Policy Compliance

Endpoint Security

Analyze endpoint policy assignments and flag endpoints with missing or outdated policies

Disconnected Endpoints

Endpoint Security

Identify endpoints that are disconnected or lost from the XSIAM instance

Agent Version Audit

Endpoint Security

Group endpoints by agent version and identify outdated installations

Endpoint Isolation Readiness

Endpoint Security

Check which endpoints support network isolation capabilities

Incident Response Metrics

Alert & Incident Management

Calculate alert response metrics and resolution rates from recent alerts

Alert Fatigue Analysis

Alert & Incident Management

Analyze alert volume, severity distribution, and identify noise patterns

External Attack Surface

Attack Surface & Playbooks

Discover internet-facing services and flag risky exposed ports

Playbook Coverage Audit

Attack Surface & Playbooks

List deployed playbooks and identify automation coverage gaps

Data Ingestion Health

Data & Detection

Check data source coverage and ingestion rates via XQL query

Correlation Rule Effectiveness

Data & Detection

Measure alert sources to assess correlation vs raw detection value

User Behavior Baseline

Data & Detection

Analyze authentication patterns and top login sources via XQL

Cloud Asset Inventory

Data & Detection

Enumerate monitored cloud workloads by provider and region

Breach Risk Reduction Trend

ROI & Operational Efficiency

Track incidents over 90 days in monthly buckets to measure breach risk reduction percentage

Tool Consolidation Savings

ROI & Operational Efficiency

Count data sources ingested into XSIAM and estimate consolidation savings

Security Posture Improvement Score

ROI & Operational Efficiency

Composite score from endpoints, alerts, services, and health metrics

Automated Threat Containment Ratio

ROI & Operational Efficiency

Measure auto-resolved vs total incidents for automation effectiveness

Data Lake Utilization Efficiency

ROI & Operational Efficiency

Analyze event types and ingestion rates via XQL for data lake usage

False Positive Reduction Benchmark

ROI & Operational Efficiency

Calculate false positive rate from alert statuses and estimate analyst savings

Payback Period Tracker

ROI & Operational Efficiency

ROI calculator from incidents, alerts, and endpoints to estimate payback period

Threat Hunting Productivity Index

ROI & Operational Efficiency

Compare proactive hunts vs reactive alerts via XQL to measure hunting productivity

Integration Coverage Audit

ROI & Operational Efficiency

Audit data sources, services, endpoints, and playbooks for integration completeness

Overall Autonomy Score

ROI & Operational Efficiency

Composite score from alert reduction, MTTR, automation, and integration coverage

Compliance and Audit Readiness

Governance & Maturity

Analyze audit management logs for compliance coverage and gap analysis

User Adoption and Training Efficiency

Governance & Maturity

Measure login frequency and unique active users from audit logs

Custom ML Model Performance

Governance & Maturity

Compare ML-driven vs rule-based alert sources for detection efficacy

Response Action Automation Coverage

Governance & Maturity

Measure auto-resolved incidents and playbook coverage for response automation

Incident Cost Reduction

Governance & Maturity

Calculate cost per incident from resolution times and estimate savings

Scalability and Performance Index

Governance & Maturity

Measure endpoint scale, alert load, event throughput, and API stability

Threat Intelligence Enrichment Ratio

Governance & Maturity

Count intel-source alerts vs total to measure threat intelligence integration

Knowledge Base Integration Utilization

Governance & Maturity

Measure playbook execution frequency as proxy for knowledge base leverage

Third-Party Integration Uptime

Governance & Maturity

Check external services status and error frequency for integration reliability

Proactive vs Reactive Workload Shift

Governance & Maturity

Classify proactive vs reactive work to measure operational maturity shift