Alert Volume Calculator
Find out how many alerts your team can realistically investigate — and how many slip through every day.
- Per-analyst alert load benchmarked against industry data
- Shows uninvestigated alert count and coverage percentage
- Models impact of false-positive reduction and automation
- Outputs a one-page capacity gap report for leadership
Calculate my alert capacity
61% uncovered
4,200 alerts/day · 14 analysts · 72% FP rate · 12 min/alert
1,176
True positives/day
720
Alerts worked/day
456
TPs missed/day
How this tool works
Enter daily alert volume
Input your current daily alert count across all sources: SIEM, EDR, cloud, identity, and network tools.
Set your team size and shift pattern
Enter analyst headcount and shift structure. We calculate per-analyst alert load and available working minutes per shift.
See the capacity gap
The calculator shows how many alerts go uninvestigated, what percentage are likely true positives, and the projected FTE gap.
What to do with the result
Identify your coverage gap
Present the uninvestigated alert count to leadership as a concrete risk exposure metric.
Size your automation need
Use the false-positive rate slider to model how much alert noise automation can eliminate.
Benchmark against industry peers
Compare your per-analyst alert load against our database of 180+ enterprise SOC benchmarks.
Alert volume calculator: frequently asked questions
What counts as an 'alert' for this calculator?
Any event that requires analyst review: SIEM correlation rules, EDR alerts, cloud security findings, identity anomaly flags, and threat intelligence hits. Do not include raw log events.
What is a reasonable false-positive rate to enter?
Industry average across SIEM and EDR sources is 65-80% false positives. If you have tuned your rules aggressively, use 45-55%. Raw out-of-the-box SIEM deployments often run 85-95% noise.
How many minutes per alert does the calculator assume?
The default is 12 minutes per alert for first-level triage and disposition. You can adjust this based on your average time-to-close metric. Complex alerts requiring investigation average 45-90 minutes.
The uninvestigated alert count seems very high — is that accurate?
For SOCs with more than 500 alerts per day and fewer than 20 analysts, uninvestigated rates of 40-70% are common in industry surveys. The Ponemon Institute found an average of 55% of alerts go unworked in understaffed SOCs.
Can I use this to justify headcount to my CISO?
Yes. Export the result as a one-page PDF that shows current alert volume, available analyst minutes, and the resulting uninvestigated alert percentage. This is a concrete risk quantification suitable for board-level conversations.
How does ManySignal reduce the uninvestigated alert count?
ManySignal's triage agent works every alert to a verdict automatically. True positives escalate to cases; false positives are dismissed with a documented rationale. The result is 100% alert coverage, regardless of volume.
Does the calculator account for shift handover overhead?
Toggle 'Include handover overhead' to deduct 15 minutes per analyst per shift for handover briefings, which reduces effective triage capacity by approximately 6%.
What if we use a managed SIEM or MDR provider?
If alerts are already filtered by an MSSP before reaching your team, enter only the alerts your team sees directly. If you want to model the raw feed, enter the full volume.
Can I model what happens if we add more analysts?
Yes. The 'Team growth' tab lets you add analyst increments and see the cost per investigated alert at each headcount level, alongside ManySignal's automation cost per alert for comparison.
Stop letting alerts pile up uninvestigated
ManySignal's triage agent works every single alert to a verdict. Book a demo to see how it handles your queue.