Friday SIEM post is here.
This week on the plate: SIEM AI enablement, transformation, or whatever fancy word we want to call it this quarter.
Where AI Actually Belongs in Your Pipeline?
We have been saying this for years. Bad data plus bad processes plus automation equals bad outcomes, faster.
With AI, the same applies. The only catch is now you get it 10x faster and at 100x scale.
Every time I say this on the blog, a podcast, or at a conference, someone asks: "OK, but what's the fix?"
And yes, I’m a big believer in not just pointing at problems without offering a direction forward.
What worked for me throughout my career is simple:
Use the right tools for the right job.
Most teams default to the path of least resistance. They bolt AI onto the end of the pipeline, which in SIEM terms means alerts. It feels like the obvious move. Alerts are where the pain is visible. But it's the wrong place to start, and now it's also the expensive place to start.
We moved from user-based pricing, where you pay a flat rate regardless of activity, to usage-based pricing, where every query, every token, every inference call costs something. That shift makes tool selection a financial decision, not just a technical one.
Burning tokens on noisy, low-quality alerts is not just inefficient. It is a budget problem.
The right sequence is this. Use AI first where it compounds. Start with your data pipeline. Fix structure, normalization, and coverage gaps. Then move to detections. Improve logic, reduce noise, raise signal quality. Only after that should you apply AI to triage and analysis.
If you skip straight to the alert layer, you are not accelerating your SOC. You are paying to automate a broken process.
Shift left. Then use AI.
Originally posted on LinkedIn on 8 May 2026.
Read the original post and the comments.


